Impact
The User Frontend WordPress plugin before version 4.3.10 fails to enforce authentication on its user directory search endpoint, allowing unauthenticated users to enumerate every registered account and retrieve email addresses and phone numbers, including those of administrators. This results in the exposure of sensitive personal information and enables attackers to launch phishing, social engineering, or spam campaigns.
Affected Systems
All WordPress sites running the User Frontend plugin older than 4.3.10 are affected. The vulnerability exists regardless of additional external security controls, as the endpoint itself performs no credential validation.
Risk and Exploitability
Because the endpoint is publicly accessible, exploitation requires only a single HTTP request with no special credentials. The lack of authentication makes this a moderate‑risk vulnerability with a CVSS score of 5.3, leading to widespread disclosure of user contact information. The EPSS score is <1%, indicating a very low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers with internet access can use this flaw to harvest email addresses and phone numbers for phishing or spam campaigns.
OpenCVE Enrichment