CVE-2026-83560: Unknown New User Approve
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
Affected products
- Unknown New User Approve: from 3.1.0, before 3.2.10 (fixed in 3.2.10)
Published 2026-09-30. Last modified 2026-09-30.