WPIntell

Source evidence

High Priority Vulneraibility

WP User Manager – User Profile Builder & Membership · support · 2025-11-06T08:16:00+00:00

mixedsentiment
highseverity
0.95relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 31 rows with source links

12.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

27 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Etienne resolved
Hi, There has been a high priority vulnerability detected on this plugin in May 2025 and it seems that there is no fix available yet. Do you plan to fix this vulnerability soon? Vulnerability: https://vdp.patchstack.com/database/wordpress/plugin/wp-user-manager/vulnerability/wordpress-wp-user-manager-plugin-2-9-12-php-object-injection-vulnerability Thanks for your help. Hi @epipo , Thanks for reaching out and for bringing this to our attention. We’re aware of the reported vulnerability, and I can confirm that our team is already working on a fix for it. While I don’t have an exact ETA yet, the patch is currently in our development pipeline and will be included in an upcoming release. In the meantime, we appreciate your patience, and we’ll make sure to update you as soon as the fix becomes available. If you have any additional questions or concerns, feel free to let us know, we’re here to help. Is this vulnerability issue resolved ? Hi, it would be very nice to get a timeline with a due date for the mitigation of the security threat. More than 6 month is really a long time for fixing a high priority security issue. Thank and greetings from Germany @robfrtlz we have contacted you frequently about this and we don’t understand how this fix is not prioritized. It should have been fixed within days. It has been more than 6 months now.

Comments

4 shown
Robert Fortaleza 2025-11-07T03:33:00+00:00

Hi @epipo , Thanks for reaching out and for bringing this to our attention. We’re aware of the reported vulnerability, and I can confirm that our team is already working on a fix for it. While I don’t have an exact ETA yet, the patch is currently in our development pipeline and will be included in an upcoming release. In the meantime, we appreciate your patience, and we’ll make sure to update you as soon as the fix becomes available. If you have any additional questions or concerns, feel free to let us know, we’re here to help.

Priyanka Behera 2025-11-19T12:31:00+00:00

Is this vulnerability issue resolved ?

buckelberg66 2025-12-03T13:53:00+00:00

Hi, it would be very nice to get a timeline with a due date for the mitigation of the security threat. More than 6 month is really a long time for fixing a high priority security issue. Thank and greetings from Germany

Studiobovenkamer 2025-12-17T14:00:00+00:00

@robfrtlz we have contacted you frequently about this and we don’t understand how this fix is not prioritized. It should have been fixed within days. It has been more than 6 months now.