PT-2025-47423 · WordPress+1 · New User Approve+1

Powpy

·

Published

2025-11-19

·

Updated

2025-11-19

·

CVE-2025-12770

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions New User Approve plugin for WordPress versions prior to 3.0.10
Description The New User Approve plugin for WordPress is susceptible to unauthorized data disclosure due to inadequate API key validation. Specifically, a loose equality comparison is used, allowing unauthenticated attackers to retrieve personally identifiable information (PII), such as usernames and email addresses of users with different approval statuses. This is achieved by exploiting PHP type juggling with the api key parameter set to "0" on sites where the Zapier API key has not been configured. The vulnerable API endpoint is the Zapier REST API.
Recommendations Update the New User Approve plugin to version 3.0.10 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-12770

Affected Products

New User Approve
Zapier Rest Api