ExploitMatch
Back

CVE-2026-88827

Monitor on ThreatCluster

Description

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.