Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
WordPress Plugin WP User Manager Cross-Site Scripting
MINI-5rxg-2777-xw37
Summary
An attacker can inject malicious code into WordPress sites using the WP User Manager plugin. This can happen if users are tricked into visiting a malicious link or if an attacker gains access to the site's administrative panel. To fix this, update the WP User Manager plugin to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| MinimOS | – | kibana-9.1 | All versions |
| MinimOS | – | kibana-9.1-advanced | All versions |
| MinimOS | – | kibana-9.1-config | All versions |
| MinimOS | – | kibana-9.1-oci-entrypoint | All versions |
Original title
MINI-5rxg-2777-xw37
Published: 1 May 2026 · Updated: 1 May 2026 · First seen: 1 May 2026