CVE-2026-18960

NONE EPSS 0.17%
Updated Aug 10, 2026
WordPress
Parameter Value
Affected Versions before 2.0.1
Vendor WordPress
Public PoC No

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.