wpNamedUsers
wpNamedUsers has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for wpNamedUsers has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. wpNamedUsers is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.9.2.
CVE-2025-48083wpNamedUsers <= 0.5 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
wpNamedUsers
Author
andriassundskard
Intranet / Extranet plugin for WordPress that allows users to specify which users and/or groups can access specific posts or pages. Current features: Select users and/or groups who will have access to posts/pages when writing/editing. Hide content of protected posts/pages. Exclude protected posts/pages from appearing in the menu. Exclude protected posts/pages from appearing in feeds. Copy permissions from one user to another. Quickly set/clear permissions of many posts/pages without opening each one. Screenshots ==. You can select which users or groups can access the content while writing a post or page. You can quickly set permissions for all your content without editing every single post or page. You can create new groups and add or remove users from groups.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C