Privilege Escalation in WPExperts User Management Plugin
CVE-2025-22736
8.8HIGH
What is CVE-2025-22736?
An Incorrect Privilege Assignment vulnerability exists in the WPExperts User Management plugin, enabling unauthorized users to escalate their privileges. This flaw affects versions from n/a up to 1.2, posing a significant security risk for WordPress sites utilizing this plugin. Attackers could exploit this vulnerability to gain higher-level access, potentially compromising the integrity of user data and site configurations.
Affected Version(s)
User Management <= 1.2