CVE-2026-4003Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. The conditional only blocks unauthenticated users when the user_id is empty, but when a non-empty user_id is supplied, execution bypasses this check entirely and proceeds to update arbitrary user meta via update_user_meta() without any authentication or authorization verification. Additionally, the nonce required for this AJAX endpoint ('userspn-nonce') is exposed to all visitors via wp_localize_script on the public wp_enqueue_scripts hook, rendering the nonce check ineffective as a security control. This makes it possible for unauthenticated attackers to update arbitrary user metadata for any user account, including the userspn_secret_token field.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 6 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-04-08: 6Mentions · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-08: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 6Technical Details · 2026-04-13: 104-0804-13
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-086
Disclosure5Patch1
2026-04-131
Disclosure1
Full discourse7 posts
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-4003、CVSS 9.8 (Critical) Users manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userspn/users-manager-pn-1115-unauthenticated-privilege-escalation-via-account-takeover-via-userspn-form-save-ajax-action

    Post summary

    A critical privilege‑escalation vulnerability (CVE‑2026‑4003) was disclosed for Users Manager – PN <= 1.1.15, allowing unauthenticated account takeover via an AJAX action. The advisory includes CVSS score and specific exploit vector details.

    00010631
    6.8K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4003 — CVSS 9.8/10 ██████████ The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ocDx43JEUl

    Post summary

    The tweet warns of a critical privilege‑escalation flaw in the WordPress PN plugin and urges users to apply a patch, but offers no details on the exploit code or active attacks.

    1000046
    16 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4003 The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due… https://www.cve.org/CVERecord?id=CVE-2026-4003

    Post summary

    The post announces CVE-2026-4003, describing a privilege escalation flaw in the Users manager – PN WordPress plugin up to version 1.1.15, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    00000182
    57.1K followersView on X
  • Abu Hurayra 🇵🇸❤️🇧🇩@HurayraIIT
    Disclosure

    CVE-2026-4003: Critical Unauthenticated Privilege Escalation in Users Manager PN Plugin (CVSS 9.8) https://hurayraiit.com/blog/cve-2026-4003-wordpress-users-manager-pn-privilege-escalation/

    Post summary

    The blog post announces CVE-2026-4003, a critical unauthenticated privilege escalation vulnerability in the WordPress Users Manager PN plugin, rated CVSS 9.8, but provides no evidence of PoC, exploitation, or patching.

    0000043
    85 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4003 Privilege Escalation via Arbitrary User Meta Update in Users Manager PN Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4003

    Post summary

    The post announces CVE-2026-4003, describing a privilege escalation flaw involving arbitrary user meta updates in the Users Manager PN Plugin, but provides no proof of concept, exploit code, patches, or evidence of active exploitation.

    0000059
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4003: CRITICAL] Users manager – PN plugin for WordPress up to v1.1.15 vulnerable to Privilege Escalation via Arbitrary User Meta Update due to flawed authorization logic in userspn_ajax_nopriv_server().#cve,CVE-2026-4003,#cybersecurity https://cvefind.com/CVE-2026-4003

    Post summary

    The tweet discloses a privilege‑escalation vulnerability in the PN plugin for WordPress up to v1.1.15, highlighting the flaw but providing no PoC, exploit code, or remediation steps.

    0000059
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4003: Users manager – PN &lt;= 1.1.15 - Un... Broken auth logic + public nonce exposure = instant admin takeover on any WordPress site running this plugin—CVSS 9.8 de... https://zerodaysignal.com/vulnerability/CVE-2026-4003 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE‑2026‑4003, a flaw in WordPress Users Manager PN ≤ 1.1.15 that allows instant admin takeover via broken authentication and public nonce exposure (CVSS 9.8); no PoC, exploit, or patch is provided.

    0000087
    204 followersView on X

Explore more