CVE-2026-77135

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 09:17

Updated : 2026-08-26 17:13


NVD link : CVE-2026-77135

Mitre link : CVE-2026-77135

CVE.ORG link : CVE-2026-77135


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key