Feed/CVE-2026-16968
CVE-2026-16968

CVE-2026-16968

Published Aug 5, 2026·Updated Aug 5, 2026

NVD Description

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free