PT-2026-69176 · WordPress · Admin Safety Guard

·

CVE-2026-16578

·

Published

2026-08-08

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection versions prior to 1.4.0
Description An issue exists where a REST API endpoint fails to perform a capability check. This allows unauthenticated attackers to retrieve a complete list of registered users, including their usernames, email addresses, roles, and two-factor authentication enrollment status, via the '/2fa/app/users' endpoint.
Recommendations Update to version 1.4.0 or later. Restrict access to the '/2fa/app/users' endpoint as a temporary mitigation measure.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16578

Affected Products

Admin Safety Guard