CVE-2026-16960: Unknown Loops & Logic
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options.
Affected products
- Unknown Loops & Logic: before 4.3.0 (fixed in 4.3.0)
Published 2026-09-09. Last modified 2026-09-09.