PT-2026-42113 · WordPress · Decent Comments

Vaibhav Narkhede

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-7385

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Decent Comments versions prior to 3.0.2
Description The Decent Comments WordPress plugin fails to restrict access to comment author and post author email addresses through its REST API endpoint. This allows unauthenticated attackers to enumerate the email addresses of registered users.
Recommendations Update to version 3.0.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-7385

Affected Products

Decent Comments