CVE-2026-77135EPSS p32.5%

CVE-2026-77135CVE-2026-77135

Description

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.

Scoring

EPSS0.41% probability of exploitation · percentile 32.5% · 2026-10-05T12:00:23Z
Last modified2026-09-28
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.