What is CVE-2026-18035?
The User Access Manager WordPress plugin fails to enforce access restrictions on REST API requests, allowing unauthenticated attackers to read content of restricted posts, pages, and custom post types. This affects versions before 2.3.15. Updating to the latest version is strongly recommended.
Azərbaycanca: User Access Manager adlı WordPress plaqini REST API sorğularına giriş məhdudiyyətlərini tətbiq etmir, bu da autentifikasiya olunmamış hücumçulara məhdudlaşdırılmış yazıların məzmununu oxumağa imkan verir. Bu zəiflik plaqinin 2.3.15-dən əvvəlki versiyalarına təsir edir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the User Access Manager plugin are affected by CVE-2026-18035?
This vulnerability affects versions of the plugin before 2.3.15.
What can an unauthenticated attacker do by exploiting CVE-2026-18035?
An unauthenticated attacker can read the content of restricted posts, pages, and custom post types.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.