CVE-2026-88827
Received Received - Intake

Authentication Bypass in Disable Users WordPress Plugin

Vulnerability report for CVE-2026-88827, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Disable Users 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Disable Users WordPress plugin through version 1.0.5 fails to enforce account-disabling controls on all authentication paths. This means an administrator may disable a user account, but the disabled user can still authenticate via XML-RPC or Application Passwords and retain full privileges.

Detection Guidance

Check if the Disable Users WordPress plugin version 1.0.5 or lower is installed. Inspect authentication logs for unauthorized access attempts via XML-RPC or Application Passwords. Verify if disabled user accounts retain full privileges.

Impact Analysis

This vulnerability allows disabled user accounts to bypass restrictions and access the WordPress site with full privileges. Attackers could exploit this to regain unauthorized access even after being disabled by an administrator.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's access control requirements. Unrestricted access via disabled accounts may result in data breaches or unauthorized modifications, undermining compliance with these regulations.

Mitigation Strategies

Update the Disable Users plugin to the latest version immediately. Disable XML-RPC if not required. Review and revoke Application Passwords for disabled accounts. Monitor user activity for suspicious logins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88827. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart