SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14567

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The User Frontend WordPress plugin prior to version 4.3.10 is vulnerable due to inadequate access controls on its user directory search endpoint, enabling unauthenticated attackers to access sensitive information such as email addresses and phone numbers of all registered users, including administrators. This vulnerability poses a significant risk to user privacy and can lead to targeted attacks or data breaches. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-14567
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
WordPress

Original NVD Description

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.