The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users.
CVE-2026-19782
NONE
EPSS 0.15%
Updated Aug 19, 2026
WordPress
CVE Details
CVE ID
CVE-2026-19782
Published Date
Aug 19, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.15%
Likelihood of exploitation in next 30 days
Percentile:
4.7th percentile (higher than 4.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory