CVE-2026-83560
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
- Published Sep 30, 2026
- CVSS 5.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available