Block User Account
Block User Account has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Block User Account has a vendor fix available, so running the current release closes it.
All of these findings were reported by Farid Narimanov. Block User Account is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-18960Block User Account <= 2.0.0 - Missing Authorization to Authenticated (Subscriber+) Account Block Bypass
Read the full analysisVulnerability Records

Block User Account
Author
Dango Web
Block User Account gives administrators complete control over user account management. Block users temporarily or permanently, set custom block messages, send email notifications, and monitor all blocking activities with detailed logs. Features: Easy User Blocking: Block any user with one click from the users list or their profile page Temporary Blocks: Set expiry dates for automatic unblocking after hours, days, or months Custom Messages: Show personalized messages to blocked users when they try to login Bulk Actions: Block or unblock multiple users at once with duration options Email Notifications: Automatically notify users and admins about blocking activities Activity Logs: Track all blocking and unblocking actions with detailed logs Dashboard Widget: Quick overview of blocked users and recent activities Admin Bar Menu: See blocked user count at a glance Export Logs: Download activity logs as CSV files Statistics Page: View blocking statistics and trends RTL Support: Fully compatible with right-to-left languages Translation Ready: Includes Persian translation Credits Developed by DangoWeb
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C