CVE-2026-83560: New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
New User Approve WordPress pluginto a version that resolves this vulnerability.Fixed in 3.2.10
Event History
Frequently Asked Questions
Which sites are exposed?
Sites running New User Approve versions earlier than 3.2.10 are exposed when the affected integration is unconfigured.
What would an attacker need to exploit this issue?
An attacker does not need to authenticate. Exploitation relies on the affected integration REST API routes being available while the integration is unconfigured.
What information could be disclosed?
The affected routes can expose registered users' IDs, usernames, email addresses, and registration dates.
What version should be used to remediate the issue?
Upgrade New User Approve to version 3.2.10 or later.