CVE 5.8 MEDIUM

Decent Comments < 3.0.2 - Unauthenticated Email Address Disclosure_CVE-2026-7385

5.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Description

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

Basic Information

ID CVE-2026-7385
Source WPScan
Published May 20, 2026 at 06:00
Modified May 20, 2026 at 17:34

Affected Product

Vendor Unknown
Product Decent Comments
Affected Versions Unknown Decent Comments 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.