What is CVE-2026-15992?
CVE-2026-15992 affects the WP Password Policy plugin for WordPress up to version 3.7.1, allowing Privilege Escalation due to missing authorization checks and nonce verification in the `get_user()` function. Users are advised to immediately update to the latest patched version or temporarily disable the plugin.
Azərbaycanca: CVE-2026-15992, WordPress üçün WP Password Policy plaginində (versiya 3.7.1-ə qədər) aşkar edilib. `get_user()` funksiyasında authorization yoxlamaları və nonce verification olmaması səbəbindən imtiyaz artırılmasına (Privilege Escalation) səbəb olur. İstifadəçilər plagini dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What plugin is affected by CVE-2026-15992 and what vulnerability does it exploit?
CVE-2026-15992 affects the WP Password Policy plugin for WordPress up to version 3.7.1. It leads to Privilege Escalation due to missing authorization checks and nonce verification in the `get_user()` function.
What should users do to protect against CVE-2026-15992?
Users should immediately update the WP Password Policy plugin to the latest patched version or temporarily disable it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.