๐Ÿ” CVE Alert

CVE-2026-88827

UNKNOWN 0.0

Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.

Vendor unknown
Product disable users
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown disable users

Be the first to know when new unknown vulnerabilities affecting unknown disable users are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Disable Users
0 โ‰ค 1.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1120d99a-9853-4b41-a2ce-d4909b19aea1/

Credits

Naoki Kawahigashi WPScan