CVE Database /
CVE-2026-18470
CVE
CVE-2026-18470 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18470
|
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 4.0.2
|
4.0.2 |
2026-08-06 |
—
|
CVE-2026-18470
The WordPress plugin "Login & Register Forms" has a vulnerability that allows an attacker to obtain the email addresses of registered users, including administrators, without needing to authenticate. This is due to the plugin not properly verifying the source of password reset requests and not adequately obscuring the email address returned in its response. As a result, an attacker can exploit this weakness to gather sensitive information about the site's users.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings