Impact
The Login & Register Forms WordPress plugin before version 4.0.2 fails to verify that a password reset request originates from the account owner and does not redact the email address returned in its response. This flaw allows any unauthenticated user to retrieve the email addresses of all registered accounts, including administrators, thereby exposing sensitive user information. The weakness corresponds to CWE‑200: Information Exposure.
Affected Systems
WordPress sites that use the Login & Register Forms plugin version less than 4.0.2 are affected. The vulnerability applies across all installations using the default password reset flow provided by the plugin.
Risk and Exploitability
Exploitation requires only unauthenticated access to the lost‑password endpoint; no credentials are needed. Because the vulnerability reveals the email addresses of all users, it poses a privacy risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation but a potential for future misuse.
OpenCVE Enrichment