VYPR

Lock User Account

by WordPress

Source repositories

CVEs (3)

  • CVE-2026-18960MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.

  • CVE-2023-4307MedSep 11, 2023
    risk 0.28cvss 4.3epss 0.00

    The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack

  • CVE-2024-11197MedNov 21, 2024
    risk 0.27cvss 4.2epss 0.00

    The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing…