CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.8. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-7385
Severity
MEDIUM
CVSS
5.8
EPSS
0.27%
WordPress
Original NVD Description
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.