Junglewise Threat Intelligence

CVE-2026-16578: Admin Safety Guard WordPress plugin authentication bypass in REST API

CVE-2026-16578 · Severity: high · CVSS 7.5 · Published 2026-08-08

Executive brief

The Admin Safety Guard WordPress plugin is used to protect WordPress sites with login security, rate limiting, and two-factor authentication. A flaw in the plugin's REST API allows unauthenticated attackers to retrieve the complete list of all registered users, including usernames, email addresses, account roles, and two-factor authentication status—enabling attackers to map targets for account compromise or social engineering.

Technical details

The plugin's REST API endpoint at /wp-json/secure-admin/v1/2fa/app/users fails to perform any capability or authentication check, exposing sensitive user data. The vulnerability is an authentication bypass and information disclosure flaw affecting the 2FA endpoint. Unauthenticated attackers can issue HTTP requests to the endpoint and retrieve full user details including usernames, display names, email addresses, roles, and 2FA enrollment status. The vulnerability is trivially exploitable via network access with no authentication or preconditions required. The issue is fixed in version 1.4.0 and later.

Affected products

  • Admin Safety Guard Admin Safety Guard before 1.4.0

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Fixed in version 1.4.0

References