SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77135

HIGH · CVSS 8.2 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows unauthorized access to sensitive user profile data, including names, emails, dates of birth, and addresses, due to inadequate verification of user records in the extension's detail view. Any visitor with access to the Detail or List plugin can exploit this flaw by supplying an arbitrary user ID. Organizations utilizing this extension should prioritize remediation to protect user privacy and prevent data breaches.

CVE
CVE-2026-77135
Severity
HIGH
CVSS
8.2
EPSS
0.24%

Original NVD Description

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.