Retour à la veille

CVE-2026-16960

Publié : 9 septembre 2026
Modifié : 9 septembre 2026
Lien officiel NVD

Description détaillée

The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options.

Références et Patchs