CVE-2026-19782
EUVD-2026-6229219.08.2026, 06:17
The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.