WordPress · Admin Safety Guard · CVE-2026-16578
**Name of the Vulnerable Software and Affected Versions**
Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection versions prior to 1.4.0
**Description**
An issue exists where a REST API endpoint fails to perform a capability check. This allows unauthenticated attackers to retrieve a complete list of registered users, including their usernames, email addresses, roles, and two-factor authentication enrollment status, via the '/2fa/app/users' endpoint.
**Recommendations**
Update to version 1.4.0 or later.
Restrict access to the '/2fa/app/users' endpoint as a temporary mitigation measure.