Impact
The User Frontend WordPress plugin before version 4.3.10 fails to enforce authentication on its user directory search endpoint. Unauthenticated users can enumerate every registered account and obtain email addresses and phone numbers, including those of administrators. This results in the exposure of sensitive personal information, allowing attackers to launch phishing, social engineering, or spam campaigns. The weakness corresponds to improper access control and information disclosure.
Affected Systems
All WordPress sites that are running User Frontend plugin older than 4.3.10 are affected. The vulnerability is present regardless of additional security measures outside the plugin, as the endpoint itself validates no credentials.
Risk and Exploitability
Because the endpoint is publicly accessible, exploitation requires only a single HTTP request and no special credentials. The lack of authentication makes this a high‑risk vulnerability with potential for mass data leakage. While an EPSS score is not available and the vulnerability is not listed in CISA KEV, the CVSS score is expected to be high due to the impact on confidentiality. Attackers with internet access can use this flaw to harvest contact information for future attacks.
OpenCVE Enrichment