๐Ÿ” CVE Alert

CVE-2026-14567

UNKNOWN 0.0

WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.

Vendor unknown
Product user frontend
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user frontend

Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Frontend
4.3.0 < 4.3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1ff904bd-cb9e-4530-afb4-6842395bb774/

Credits

Revanth Hari Narayana Matte WPScan