CVE-2026-88827 PUBLISHED

Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords

Assigner: WPScan
Reserved: 10.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.

Product Status

Vendor Unknown
Product Disable Users
Versions Default: unknown
  • affected from 0 to 1.0.5 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE