Loading market data...
← Back to CVE feed

CVE-2026-83560

MEDIUM CVSS 5.3 View on NVD ↗

Description

The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 30, 2026 06:17 UTC Modified: Sep 30, 2026 16:28 UTC