CVE-2026-14567 PUBLISHED

WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory

Assigner: WPScan
Reserved: 03.07.2026 Published: 28.08.2026 Updated: 28.08.2026

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.

Product Status

Vendor Unknown
Product User Frontend
Versions Default: unaffected
  • affected from 4.3.0 to 4.3.10 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE