CVE-2026-16960: Loops & Logic < 4.3.0 - Unauthenticated User Data and Site Option Disclosure
The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/loops-and-logicto a version that resolves this vulnerability.Fixed in 4.3.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated visitor can exploit it. No WordPress account or authenticated session is required.
What information may be exposed?
An attacker can read arbitrary WordPress user records, including email addresses and roles, as well as arbitrary site options.
Are sites running the default public-facing functionality affected?
The affected functionality is a public template-data action, so exposure may be reachable by unauthenticated visitors where the vulnerable plugin version is installed.
How can I determine whether my site is affected?
Check whether Loops & Logic is installed and whether its version is earlier than 4.3.0. Versions before 4.3.0 are affected.