The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.
References
Configurations
No configuration.
History
20 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.8 |
20 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-20 07:16
Updated : 2026-06-17 11:02
NVD link : CVE-2026-7385
Mitre link : CVE-2026-7385
CVE.ORG link : CVE-2026-7385
JSON object : View
Products Affected
No product.
CWE
No CWE.
