{"id":"CVE-2026-16968","published":"2026-08-05T07:16:36.877","lastModified":"2026-08-05T16:16:53.677","description":"The GeoDirectory  WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/d7a4e3ee-507d-44fb-9386-27ad67158cdc/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows any authenticated user with Contributor-level access or higher to retrieve email addresses of all registered users, including administrators, due to lack of proper user restriction checks in GeoDirectory WordPress plugin versions before 2.8.168.","exploitability":"Exploitation is relatively straightforward for attackers who have basic contributor access or higher, requiring only authentication and knowledge of the flaw.","blast_radius":"If exploited, this could lead to significant privacy breaches, as email addresses of all users, including administrators, are exposed.","remediation":"Update GeoDirectory WordPress plugin to version 2.8.168 or later to apply necessary security patches and restrictions.","tags":["auth-bypass","privacy","wordpress","user-data"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:06:42.323Z"}}