User Access Manager
User Access Manager has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2011 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (38%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization.
Every one of the 8 issues recorded for User Access Manager has a vendor fix available, so running the current release closes all known holes.
7 independent researchers contributed these findings, most of them (2) reported by Neven Birusk. User Access Manager is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2011-5328User Access Manager < 1.2 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
User Access Manager
Author
gm_alex
The “User Access Manager”-plugin for WordPress allows you to manage the access of your content. This is useful if you need a member area, a private section at your blog, or you want that other people can write at your blog but not everywhere. Including all post type (post, pages etc.), taxonomies (categories etc.) and files by creating user groups. Just assign the content you want to restrict und and your registered users which should have access to a group. From now on the content is only accessible and writable for the specified group. Try it out You can try it out at TasteWP.com before install: Try user access manager (affiliate link) Feature list User groups Set separate access for readers and editors Set access by user groups Set default user groups Set time based access User-defined post type (posts, pages etc.) title (if no access) User-defined post type (posts, pages etc.) text (if no access) Optional login form (if no access) User-defined comment text (if no access) Hide complete post types (posts, pages etc.) Hide elements in the navigation Redirecting users to other pages (if no access) Recursive locking of content Limited access to uploaded files Full integrated at the admin panel Multilingual support Also protect your rss feeds Give access by IP-address Plugin-Api to use the User Access Manager in your on plugins or extend other plugins UAMPPE like behaviour is now build in (Expect negation like !groupName and showprivate and shownotauthorized parameter) Included languages See https://translate.wordpress.org/projects/wp-plugins/user-access-manager The documentation can be found here: https://github.com/GM-Alex/user-access-manager/wiki Please report bugs and feature requests here: https://github.com/GM-Alex/user-access-manager/issues If you are a developer and want to contribute please visit https://github.com/GM-Alex/user-access-manager For general questions, like how to set up, best practice and so on please use the support thread here (don’t post issues here): https://wordpress.org/support/plugin/user-access-manager To stay up-to-date follow me on Twitter: GMAlex on Twitter
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C