PT-2026-103027 · WordPress · New User Approve
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
New User Approve WordPress plugin versions prior to 3.2.10
Description
Insufficient authentication verification on integration REST API endpoints occurs when the integration is unconfigured. This allows unauthenticated attackers to retrieve personal data of registered users, including
id, username, email address, and registration date.Recommendations
Update New User Approve WordPress plugin to version 3.2.10 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
New User Approve