PT-2025-50891 · WordPress · Wordpress+1

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-13660

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Guest Support plugin for WordPress versions prior to 1.2.4
Description The software contains a flaw that allows unauthorized disclosure of user email addresses. An unauthenticated attacker can enumerate user accounts and extract email addresses by accessing a public AJAX endpoint. The vulnerable endpoint is /wp-admin/admin-ajax.php with the guest support handler parameter set to ajax and the request parameter set to get users. This allows retrieval of user information without any authentication or capability checks.
Recommendations Update the Guest Support plugin to version 1.2.4 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-13660

Affected Products

Guest Support
Wordpress