New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure
New User Approve
Minimum safe version
3.2.4
Update to 3.2.4 or later to address 16 fixable vulnerabilities
CVE-2026-25390
CVE-2025-69063
CVE-2025-63030
CVE-2025-12770
CVE-2024-54323
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress New User Approve Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)
New User Approve < 2.4.1 - Reflected Cross-Site Scripting
WordPress New User Approve Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
New User Approve <= 2.4 - Reflected Cross-Site Scripting
CVE-2022-1625
WordPress New User Approve plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress New User Approve plugin <= 2.0 - Sensitive Information Disclosure vulnerability
WordPress New User Approve plugin <= 2.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability