Impact
The vulnerability originates from a missing capability check in the handle_filter_users function of the Ultimate Member Widgets for Elementor plugin. This flaw allows attackers without authentication to retrieve the first name, last name, and email address of all WordPress users. Such partial data exposure can facilitate targeted phishing, identity theft, or further compromise of user accounts, impacting the privacy of site members.
Affected Systems
WordPress sites running the Ultimate Member Widgets for Elementor – WordPress User Directory plugin versions 2.3 or earlier are affected. The issue applies to all installations of the plugin distributed by userelements.
Risk and Exploitability
This weakness carries a CVSS score of 5.3 and a very low EPSS probability of less than 1%, indicating that exploitation is unlikely to be widespread but the risk remains present. The vulnerability is not listed in CISA's KEV catalog. An attacker can exploit it by sending unauthenticated requests to the endpoint that invokes handle_filter_users, effectively bypassing authorization checks to gain user metadata.
OpenCVE Enrichment