The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
CVE-2026-18960
NONE
EPSS 0.17%
Updated Aug 10, 2026
WordPress
CVE Details
CVE ID
CVE-2026-18960
Published Date
Aug 10, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
6.7th percentile (higher than 6.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory