WP User Merger
WP User Merger has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2022; all 3 are fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 3 high. 2022 was the busiest year with 3 disclosures.
The most common weakness is SQL Injection, behind 3 of the records (100%).
Every one of the 3 issues recorded for WP User Merger has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Kunal Sharma. WP User Merger is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2022-3848WP User Merger <= 1.5.2 - Authenticated (Admin+) SQL Injection
Read the full analysisVulnerability Records

WP User Merger
Author
Fahad Mahmood
Author: Fahad Mahmood Project URI: http://androidbubble.com/blog/wordpress/plugins/wp-user-merger Demo URI: http://demo.androidbubble.com/user-merger After activation there will be a settings page under Users menu. User Merger let you merge information of two users. There are two dropdowns on settings page. Select two users you want to merge. For example display name, user ID, login and email etc. It is a user friendly plugin to merge multiple user accounts. See screenshot 1. Then press “Merge Users” button. A warning notification will appear for confirmation. Confirm action by pressing the Yes button. See screenshot 2. After pressing proceed there will be a successful message which means users has been merged successfully. See screenshot 3. If you select same users, the merge action will not be performed. A warning message will appear that same users cannot be selected for merge action. See screenshot 4. For detailed selection there is a toggle button that allow you to choose what information the user should include after the merge action. This is a premium feature. See screenshot 5. Tags wordpress, users, merge License This WordPress plugin is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This WordPress plugin is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this WordPress plugin. If not, see http://www.gnu.org/licenses/gpl-2.0.html.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C