Junglewise Threat Intelligence

CVE-2026-18365: WordPress zportals plugin unauthenticated information disclosure

CVE-2026-18365 · Severity: medium · CVSS 4.3 · Published 2026-09-23

Executive brief

The zportals WordPress plugin before version 6.4.2 contains an AJAX action lacking security checks that allows any subscriber-level user to retrieve the display names and email addresses of all registered WordPress users, including administrators. An attacker with a basic account can exploit this to harvest sensitive user information without authorization, potentially enabling phishing campaigns or account takeover attacks.

Technical details

The vulnerability stems from missing capability and nonce validation on an AJAX action in the zportals plugin, allowing low-privileged users (subscriber level and above) to bypass access controls. The affected AJAX endpoint exposes user directory information including display names and email addresses for all registered accounts. Exploitation requires only an existing subscriber account and network access to the WordPress installation; the issue was patched in version 6.4.2.

Affected products

  • Zportals zportals before 6.4.2

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in version 6.4.2

References

Related threats