PLUGIN SECURITY
Is Wp User Manager safe?
The most customizable profiles & community builder WordPress plugin with front-end login, registration, profile customization and content restriction.
What this plugin does
- Slug:
wp-user-manager - Author: WP User Manager
- 10000+ active installs
- 94/100 rating (350 reviews on wordpress.org)
- 726255 all-time downloads
- On WordPress.org since 2015-07-06
communitymembersmembershipuser profileUser Registration
Maintenance status
- Latest known version: 2.9.18
- Last updated: 2026-05-30 9:54am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
8 known CVEs on file for Wp User Manager. Reported between 2021 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-9290 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.18 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 2.9.18 | 2.9.18 | 2026-06-05 | ✓ fixed in latest |
| CVE-2026-49766 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.17 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.9 | < 2.9.17 | 2.9.17 | 2026-06-05 | ✓ fixed in latest |
| CVE-2025-13320 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 | External Control of File Name or Path | Medium 6.8 | < 2.9.13 | 2.9.13 | 2025-12-11 | ✓ fixed in latest |
| CVE-2025-60245 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 | Deserialization of Untrusted Data | Critical 9.8 | < 2.9.13 | 2.9.13 | 2025-05-19 | ✓ fixed in latest |
| CVE-2024-10216 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12 | Missing Authorization | Medium 4.3 | < 2.9.12 | 2.9.12 | 2024-11-22 | ✓ fixed in latest |
| CVE-2024-10537 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12 | Missing Authorization | Medium 4.3 | < 2.9.12 | 2.9.12 | 2024-11-22 | ✓ fixed in latest |
| CVE-2024-43336 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.11 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.9.11 | 2.9.11 | 2024-08-16 | ✓ fixed in latest |
| CVE-2021-24655 | WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.6.3 | Authorization Bypass Through User-Controlled Key | High 7.5 | < 2.6.3 | 2.6.3 | 2021-09-22 | ✓ fixed in latest |
How to fix it
Keep Wp User Manager updated — 2.9.18 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — 200000+ active installs — 88/100 (1444) — max PHP 8.4
- BuddyPress — 90000+ active installs — 82/100 (375) — max PHP <8.0
- Simple Membership — 40000+ active installs — 92/100 (475) — max PHP 8.4
- Ultimate Member – reCAPTCHA — 20000+ active installs — 74/100 (11) — max PHP 8.4
- wpForo Forum — 20000+ active installs — 94/100 (390)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.