Security Advisory

CVE-2026-19782

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 06:00:21
Last updated 2026-08-19 16:39:16
Assigner WPScan
CVSS score 5.4
State PUBLISHED

Description

The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users.