Multiple high-severity flaws in WordPress plugins exposed sites to account takeover and, in one case, possible remote code execution. In Users Manager PN, tracked as CVE-2026-4003, a missing authorization check in the userspn_ajax_nopriv_server() handler let unauthenticated attackers overwrite arbitrary user metadata through the userspn_form_save AJAX action. Because the required userspn-nonce was reportedly exposed on public pages, attackers could abuse the bug with a single crafted request to modify profiles and potentially seize control of administrator accounts. The issue affected versions through 1.1.15 and was reportedly fixed in 1.1.20.
Two additional vulnerabilities were disclosed in WP Captcha PRO affecting versions through 5.38. CVE-2026-5415 allowed Subscriber-level users or higher to generate temporary login links for arbitrary accounts because the ajax_run_tool() AJAX handler checked only a nonce and not user capabilities, enabling authentication bypass and administrator takeover. Separately, CVE-2026-5411 allowed authenticated low-privilege users to upload attacker-controlled files by poisoning license metadata and abusing sync_cloud_protection() to download and extract content into a web-accessible uploads directory; if PHP execution was possible and allow_url_fopen was enabled for remote retrieval, the flaw could be escalated to remote code execution via a webshell.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A high-severity arbitrary file upload vulnerability was disclosed in WP Captcha PRO affecting versions up to and including 5.38. The flaw can let authenticated Subscriber-level users upload attacker-controlled files, potentially leading to remote code execution via webshell deployment.
A high-severity authentication bypass vulnerability was disclosed in WP Captcha PRO affecting versions up to and including 5.38. The flaw allows authenticated Subscriber-level users or higher to generate temporary login links for arbitrary users and log in as them, including administrators.
A critical unauthenticated privilege-escalation vulnerability was disclosed in the WordPress Users Manager PN plugin. The flaw allows arbitrary user metadata updates and potential takeover of any account, including administrators, using a publicly exposed nonce.
The vendor reportedly fixed a critical missing-authorization flaw in the WordPress Users Manager PN plugin in version 1.1.20. The issue affected all versions up to and including 1.1.15 and could allow unauthenticated account takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.