CVE-2026-19782

NONE EPSS 0.15%
Updated Aug 19, 2026
WordPress
Parameter Value
Affected Versions before 1.33.5
Vendor WordPress
Public PoC No

The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users.