PT-2026-69176 · WordPress · Admin Safety Guard
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection versions prior to 1.4.0
Description
An issue exists where a REST API endpoint fails to perform a capability check. This allows unauthenticated attackers to retrieve a complete list of registered users, including their usernames, email addresses, roles, and two-factor authentication enrollment status, via the '/2fa/app/users' endpoint.
Recommendations
Update to version 1.4.0 or later.
Restrict access to the '/2fa/app/users' endpoint as a temporary mitigation measure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin Safety Guard