wpNamedUsers

wpNamedUsers has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for wpNamedUsers has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. wpNamedUsers is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.9.2.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all wpNamedUsers vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-48083

wpNamedUsers <= 0.5 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv0.5
0.0(0)
0/100
Last Updated
2011-03-03 (16y ago)
Active Installs
40+
Downloads
14,581
Requires WP
2.6+
Requires PHP
0+
Tested up to
WP 2.9.2
Created
2008-09-18 (18y ago)

Intranet / Extranet plugin for WordPress that allows users to specify which users and/or groups can access specific posts or pages. Current features: Select users and/or groups who will have access to posts/pages when writing/editing. Hide content of protected posts/pages. Exclude protected posts/pages from appearing in the menu. Exclude protected posts/pages from appearing in feeds. Copy permissions from one user to another. Quickly set/clear permissions of many posts/pages without opening each one. Screenshots ==. You can select which users or groups can access the content while writing a post or page. You can quickly set permissions for all your content without editing every single post or page. You can create new groups and add or remove users from groups.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C