New User Approve
cpe:2.3:a:wpexperts:new_user_approve:*:*:*:*:wordpress:*:*
- <= 3.2.2
A vulnerability exists in the New User Approve plugin for WordPress, in all versions through 3.2.2, due to a lack of proper capability checks on several REST API endpoints. This oversight enables unauthenticated attackers to approve or deny user accounts, access sensitive user information such as emails and roles, and forcibly log out privileged users.
Exploitation of this vulnerability could lead to unauthorized user account management and disclosure of sensitive user information.
The vulnerability can be reproduced by sending requests to the affected REST API endpoints without authentication. The missing capability checks allow for unauthorized approval or denial of user accounts, as well as access to sensitive user details.
Users are advised to update the New User Approve plugin to version 3.2.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.