The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to approve or deny user accounts, retrieve sensitive user information including emails and roles, and force logout of privileged users.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 07:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-28T06:43:45.651Z
Updated: 2026-01-28T14:48:01.546Z
Reserved: 2026-01-09T21:21:53.121Z
Link: CVE-2026-0832
Updated: 2026-01-28T14:47:50.610Z
Status : Awaiting Analysis
Published: 2026-01-28T07:16:00.320
Modified: 2026-01-29T16:31:35.700
Link: CVE-2026-0832
No data.