haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-120975.3medium[patched]

Unauthenticated Plugin Settings Modification

TARGET ECOSYSTEM / VENDORUser Management
AFFECTED PRODUCTUser Management (<= 1.2)
CWE CLASSIFICATIONCWE-862: Missing Authorization
PUBLISHED DATE2026-07-07

Summary

User Management (<= 1.2) is vulnerable to an authorization bypass due to missing capability checks. This allows unauthenticated attackers to arbitrarily modify the plugin’s export field configurations and expose sensitive user information.