๐Ÿ” CVE Alert

CVE-2026-83560

UNKNOWN 0.0

New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.

Vendor unknown
Product new user approve
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown new user approve

Be the first to know when new unknown vulnerabilities affecting unknown new user approve are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / New User Approve
3.1.0 < 3.2.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/

Credits

Suhayb Ahmed (cyboltx) WPScan