PT-2026-1588 · WordPress · Latest Registered Users

Abhirup Konwar

·

Published

2026-01-07

·

Updated

2026-02-02

·

CVE-2025-13493

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Latest Registered Users plugin for WordPress versions prior to 1.5
Description The Latest Registered Users plugin for WordPress is susceptible to unauthorized user data export. This is a result of a lack of authorization and nonce validation within the rnd handle form submit function, which is connected to the admin post my simple form and admin post nopriv my simple form actions. An unauthenticated attacker can potentially export complete user details (excluding passwords and sensitive tokens) in CSV format by manipulating the action parameter.
Recommendations Update The Latest Registered Users plugin to version 1.5 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13493

Affected Products

Latest Registered Users