
🚨*CVE* CVE-2026-18035 The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the con… https://www.cve.org/CVERecord?id=CVE-2026-18035 ----- Traducción: CVE-2026-18035 El … http://infoflow.cloud`
Post summary
This post announces CVE‑2026‑18035, describing a missing access check in the User Access Manager WordPress plugin that permits unauthenticated REST API reads.

