← Back to search

CVE-2026-16968

6.5 MEDIUM

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
This flaw allows any authenticated user with Contributor-level access or higher to retrieve email addresses of all registered users, including administrators, due to lack of proper user restriction checks in GeoDirectory WordPress plugin versions before 2.8.168.
Exploitability
Exploitation is relatively straightforward for attackers who have basic contributor access or higher, requiring only authentication and knowledge of the flaw.
Blast radius
If exploited, this could lead to significant privacy breaches, as email addresses of all users, including administrators, are exposed.
Prioritized remediation
Update GeoDirectory WordPress plugin to version 2.8.168 or later to apply necessary security patches and restrictions.
auth-bypassprivacywordpressuser-data

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.