Impact
The WPS Bidouille WordPress plug‑in version 1.33.4 and earlier allows any authenticated user, including subscribers, to invoke the AJAX action wps_get_users. Because this action lacks proper authorisation checks, it returns the email addresses of all registered users, breaching confidentiality of personal contact information. This weakness corresponds to CWE‑200, an information disclosure vulnerability.
Affected Systems
All WordPress installations that have the WPS Bidouille plug‑in installed with a version earlier than 1.33.5 are impacted. The plug‑in is identified as Unknown:WPS Bidouille and functions to modify website behaviour. Site administrators should verify the plug‑in version and upgrade if necessary.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 5.4, indicating a moderate risk level. The EPSS score is listed as less than 1%, suggesting that public exploitation is currently low. The plug‑in is not listed in the CISA KEV catalog. Attackers must first authenticate to the WordPress site; any user with login credentials can trigger the unsecured AJAX endpoint repeatedly to harvest all user e‑mail addresses. Based on the description, the attack vector is authenticated and the exposure is for all users.
OpenCVE Enrichment