Impact
The zportals WordPress plugin, in versions prior to 6.4.2, contains an AJAX action that is called without performing a capability or nonce verification. A subscriber‑level account can trigger this endpoint and receive the display name and email address for every user on the site, including administrators. This flaw results in the unintended public disclosure of personal user information and is identified as a CWE‑200 weakness.
Affected Systems
The vulnerability affects WordPress sites that have the zportals plugin installed with a version earlier than 6.4.2. The plugin is listed as a vendor product of Unknown:zportals, and no other affected versions are specified beyond the generic pre‑6.4.2 range.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity assessment. The EPSS score being less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is the AJAX endpoint, and it requires an authenticated subscriber account to trigger. Successful exploitation does not provide privilege escalation or code execution, only access to user contact data.
OpenCVE Enrichment