{"id":"CVE-2026-83560","title":"The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, u…","summary":"The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, u…","severity":"none","cwe":["CWE-200"],"product":"New User Approve","affected":["new_user_approve >= 3.1.0 < 3.2.10"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:05.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-83560","references":[{"url":"https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.551Z","slug":"CVE-2026-83560","body":"## Overview\n\nThe New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}