What is CVE-2026-16578?
This vulnerability affects "The Admin Safety Guard" WordPress security plugin versions before 1.4.0. Because no capability check is performed on a REST API endpoint, unauthenticated attackers can retrieve the full list of registered users including their usernames and emails. Updating to the latest version of the plugin is recommended.
Azərbaycanca: Bu boşluq "The Admin Safety Guard" adlı WordPress təhlükəsizlik plagininin 1.4.0-dan əvvəlki versiyalarına təsir edir. REST API üzərində icazə yoxlaması aparılmadığı üçün autentifikasiya olunmamış hücumçular bütün qeydiyyatdan keçmiş istifadəçilərin siyahısını, o cümlədən istifadəçi adları və e-poçtlarını əldə edə bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and versions are affected by CVE-2026-16578?
This vulnerability affects "The Admin Safety Guard" WordPress security plugin versions before 1.4.0.
What information can an unauthenticated attacker obtain by exploiting CVE-2026-16578?
Attackers can retrieve the full list of registered users including their usernames and emails.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.