---
id: CVE-2026-83560
title: >-
  The New User Approve WordPress plugin before 3.2.10 does not properly verify
  authentication on a set of integration REST API routes when the integration is
  unconfigured, allowing unauthenticated attackers to retrieve personal data
  (id, u…
summary: >-
  The New User Approve WordPress plugin before 3.2.10 does not properly verify
  authentication on a set of integration REST API routes when the integration is
  unconfigured, allowing unauthenticated attackers to retrieve personal data
  (id, u…
severity: none
cwe:
  - CWE-200
product: New User Approve
affected:
  - new_user_approve >= 3.1.0 < 3.2.10
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:05.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83560'
references:
  - url: 'https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.551Z'
---

## Overview

The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
