Impact
This vulnerability lies in the Admin Safety Guard WordPress plugin, version 1.4.0 and earlier. One of its REST API endpoints performs no capability check, allowing any unauthenticated user to read a complete list of registered users, including usernames, email addresses, roles, and two‑factor authentication enrollment status. The primary impact is the disclosure of sensitive user information, potentially aiding credential‑replay or social‑engineering attacks. The weakness corresponds to Improper Authorization, where access controls fail to enforce authentication or authorization for a restricted operation.
Affected Systems
The affected system is the Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin, all releases prior to 1.4.0. Users of the plugin who have not yet upgraded are susceptible; the vulnerability does not discriminate by user role, so any visitor to the site can exploit it.
Risk and Exploitability
The CVSS score is not provided and EPSS is not available, but because the flaw allows unauthenticated access to private user data, the risk is elevated. The vulnerability is not listed in CISA's KEV catalog, yet the absence of authentication checks makes exploitation trivial for attackers with network visibility to the site’s REST API. Absence of capability verification means any external actor can retrieve the data without further prerequisites.
OpenCVE Enrichment