Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7385

Опубликовано: 20 мая 2026
Источник: nvd
CVSS3: 5.8
EPSS Низкий

Описание

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

EPSS

Процентиль: 19%
0.00271
Низкий

5.8 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.8
github
3 месяца назад

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

EPSS

Процентиль: 19%
0.00271
Низкий

5.8 Medium

CVSS3

Дефекты