CyberRota Analysis
AI-GeneratedThe User Frontend WordPress plugin prior to version 4.3.10 is vulnerable due to inadequate access controls on its user directory search endpoint, enabling unauthenticated attackers to access sensitive information such as email addresses and phone numbers of all registered users, including administrators. This vulnerability poses a significant risk to user privacy and can lead to targeted attacks or data breaches. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk.
Original NVD Description
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.