Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin WP User Manager Cross-Site Scripting

MINI-5rxg-2777-xw37
Summary

An attacker can inject malicious code into WordPress sites using the WP User Manager plugin. This can happen if users are tricked into visiting a malicious link or if an attacker gains access to the site's administrative panel. To fix this, update the WP User Manager plugin to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
MinimOS kibana-9.1 All versions
MinimOS kibana-9.1-advanced All versions
MinimOS kibana-9.1-config All versions
MinimOS kibana-9.1-oci-entrypoint All versions
Original title
MINI-5rxg-2777-xw37
Published: 1 May 2026 · Updated: 1 May 2026 · First seen: 1 May 2026