CVE-2026-88827
Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
| Vendor | unknown |
| Product | disable users |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown disable users
Be the first to know when new unknown vulnerabilities affecting unknown disable users are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Disable Users
0 โค 1.0.5
References
Credits
Naoki Kawahigashi WPScan