PT-2025-50891 · WordPress · Wordpress+1
Published
2025-12-12
·
Updated
2025-12-12
·
CVE-2025-13660
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Guest Support plugin for WordPress versions prior to 1.2.4
Description
The software contains a flaw that allows unauthorized disclosure of user email addresses. An unauthenticated attacker can enumerate user accounts and extract email addresses by accessing a public AJAX endpoint. The vulnerable endpoint is
/wp-admin/admin-ajax.php with the guest support handler parameter set to ajax and the request parameter set to get users. This allows retrieval of user information without any authentication or capability checks.Recommendations
Update the Guest Support plugin to version 1.2.4 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guest Support
Wordpress