CVE-2026-83560
Description
AI Translation Available
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/