CVE-2026-14567
WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
| Vendor | unknown |
| Product | user frontend |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user frontend
Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Frontend
4.3.0 < 4.3.10
References
Credits
Revanth Hari Narayana Matte WPScan