CVE-2026-83560
New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
| Vendor | unknown |
| Product | new user approve |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown new user approve
Be the first to know when new unknown vulnerabilities affecting unknown new user approve are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / New User Approve
3.1.0 < 3.2.10
References
Credits
Suhayb Ahmed (cyboltx) WPScan