CVE-2026-18365
Zportals < 6.4.2 - Subscriber+ User Email Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user, including administrators.
| Vendor | unknown |
| Product | zportals |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown zportals
Be the first to know when new unknown vulnerabilities affecting unknown zportals are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / zportals
0 < 6.4.2
References
Credits
Erwan LR (WPScan) WPScan