PoC Index

CVE-2026-14567

MEDIUM 5.3EPSS 0.3%

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.25% chance of exploitation in the next 30 days, 16th percentile
Published
2026-08-28

Proof-of-concept exploits (1)

References

Related