PatchSiren cyber security CVE debrief
CVE-2026-4003 felixmartinez CVE debrief
The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. The conditional only blocks unauthenticated users when the user_id is empty, but when a non-empty user_id is supplied, execution bypasses this check entirely and proceeds to update arbitrary user meta via update_user_meta() without any authentication or authorization verification. Additionally, the nonce required for this AJAX endpoint ('userspn-nonce') is exposed to all visitors via wp_localize_script on the public wp_enqueue_scripts hook, rendering the nonce check ineffective as a security control.
- Vendor
- felixmartinez
- Product
- Users manager – PN
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
This vulnerability affects users of the Users manager – PN plugin for WordPress, particularly those with versions up to and including 1.1.15. Unauthenticated attackers can exploit this vulnerability to update arbitrary user metadata for any user account, including the userspn_secret_token field.
Technical summary
The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update. The vulnerability exists due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function. An unauthenticated attacker can exploit this vulnerability to update arbitrary user metadata, including the userspn_secret_token field. This issue affects all versions up to and including 1.1.15 of the plugin. The vulnerability is caused by the userspn_ajax_nopriv_server() function not properly verifying authentication or authorization before updating user meta via update_user_meta(). Additionally, the nonce required for the AJAX endpoint 'userspn-nonce' is exposed to all visitors via wp_localize_script on the public wp_enqueue_scripts hook, which makes the nonce check ineffective.
Defensive priority
High
Recommended defensive actions
- Update the Users manager – PN plugin to a version beyond 1.1.15
- Restrict access to the AJAX endpoint 'userspn-nonce'
- Monitor user meta updates for suspicious activity
- Implement additional authentication and authorization checks for user meta updates
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was reported by [email protected]. The CVE record was published on 2026-04-08T05:16:06.347Z and last modified on 2026-07-24T21:10:00.143Z. Evidence is limited to reporter claims and CVE details. Defenders should verify affected versions, review plugin code for update_user_meta() calls, and monitor user meta updates for suspicious activity. The nonce exposure via wp_localize_script on the public wp_enqueue_scripts hook should be verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4003 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4003
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4003 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4003
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-common.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-functions-user.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-ajax-nopriv.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-ajax-nopriv.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.