Executive brief
The Login & Register Forms WordPress plugin allows unauthenticated attackers to discover registered users' email addresses through a flaw in its password reset functionality. When configured with the verification-code reset mode (a non-default setting), the plugin returns inadequately masked email addresses in response to password reset requests, and does not verify that requests come from the account owner. This enables attackers to enumerate and extract contact information for all users, including site administrators, without authentication or authorization.
Technical details
The vulnerability is an information disclosure flaw (CWE-200) in the password reset feature of the Login & Register Forms plugin (versions 3.0.0–4.0.1). When configured to use verification-code reset mode, the plugin's AJAX endpoint (xoo_el_form_action) accepts unauthenticated requests with a username parameter and returns the associated account's email address. The email masking is insufficient: the redacted format reveals the structure and can be reverse-engineered through repeated requests to confirm candidate addresses. Additionally, when an account's username is email-shaped, the stored address is returned completely unmasked. The vulnerability requires network access to the WordPress site and is reachable via POST to wp-admin/admin-ajax.php. The default reset mode ("Send Reset Link") is not affected. The issue was patched in version 4.0.2.
Affected products
- Easy Login and Register Forms Login & Register Forms 3.0.0 to 4.0.1
Timeline
- 2026-08-05: disclosed
- 2026-04: patched: Fixed in version 4.0.2
- 2026-08-10: advisory