CVE-2026-16968
6.5 MEDIUMPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- This flaw allows any authenticated user with Contributor-level access or higher to retrieve email addresses of all registered users, including administrators, due to lack of proper user restriction checks in GeoDirectory WordPress plugin versions before 2.8.168.
- Exploitability
- Exploitation is relatively straightforward for attackers who have basic contributor access or higher, requiring only authentication and knowledge of the flaw.
- Blast radius
- If exploited, this could lead to significant privacy breaches, as email addresses of all users, including administrators, are exposed.
- Prioritized remediation
- Update GeoDirectory WordPress plugin to version 2.8.168 or later to apply necessary security patches and restrictions.
auth-bypassprivacywordpressuser-data
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.