Description
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
Published: 2026-08-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Login & Register Forms WordPress plugin before version 4.0.2 fails to verify that a password reset request originates from the account owner and does not redact the email address returned in its response. This flaw allows any unauthenticated user to retrieve the email addresses of all registered accounts, including administrators, thereby exposing sensitive user information. The weakness corresponds to CWE‑200: Information Exposure.

Affected Systems

WordPress sites that use the Login & Register Forms plugin version less than 4.0.2 are affected. The vulnerability applies across all installations using the default password reset flow provided by the plugin.

Risk and Exploitability

Exploitation requires only unauthenticated access to the lost‑password endpoint; no credentials are needed. Because the vulnerability reveals the email addresses of all users, it poses a privacy risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation but a potential for future misuse.

Generated by OpenCVE AI on August 10, 2026 at 08:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Login & Register Forms plugin to version 4.0.2 or later to address the email disclosure flaw
  • If an immediate upgrade is not possible, disable the password reset feature for unauthenticated users or restrict its availability through plugin settings or a temporary access‑control configuration
  • Sanitize and suppress any user‑related data that is output in error or status messages during the password reset process, following the guidance for information‑exposure mitigation

Generated by OpenCVE AI on August 10, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
Title Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T06:00:12.383Z

Reserved: 2026-07-31T09:02:16.331Z

Link: CVE-2026-18470

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T08:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor