CVE-2026-18035
User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
| Vendor | unknown |
| Product | user access manager |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user access manager
Be the first to know when new unknown vulnerabilities affecting unknown user access manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Access Manager
0 < 2.3.15
References
Credits
Farid Narimanov WPScan