Add User Autocomplete
Add User Autocomplete has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.3 out of 10.
The most common weakness is Improper Privilege Management, behind 1 of the records (100%).
The one issue recorded for Add User Autocomplete has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Huu Do. Add User Autocomplete is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-87759Add User Autocomplete < 1.2 - Authenticated (Subscriber+) Privilege Escalation
Read the full analysisVulnerability Records
Add User Autocomplete
Author
Boone Gorges
WordPress Multisite’s Add Existing User field requires you to type the username or email address of an existing user. This plugin makes this job a bit easier, by adding autocomplete functionality to the Add Existing User box. It also allows you to add multiple users at a time. NOTE: Based in part on this plugin, WordPress 3.4+ has built-in autocomplete throughout much of the Network Admin. If you wish to use WP’s native autocomplete, do not use this plugin. However, Add User Autocomplete has some features that WP’s version does not (the ability to add multiple users, search by display name); activating AUA will disactivate WP’s autocomplete.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C