CVE-2026-18365: Zportals < 6.4.2 - Subscriber+ User Email Disclosure
Published Sep 23, 2026
·Updated
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user, including administrators.
Affected Software
1 affected component
zportals zportals WordPress plugin<6.4.2
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated user with a subscriber-level account can exploit the affected AJAX action. This includes low-privileged accounts that would not normally be able to access other users' email addresses.
2
What information can be disclosed?
The issue allows disclosure of the display name and email address of every registered WordPress user, including administrator accounts.
3
Are installations running version 6.4.2 affected?
No. The issue affects versions before 6.4.2.