CVE

CVE-2026-18470 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18470 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 4.0.2 4.0.2 2026-08-06

CVE-2026-18470

The WordPress plugin "Login & Register Forms" has a vulnerability that allows an attacker to obtain the email addresses of registered users, including administrators, without needing to authenticate. This is due to the plugin not properly verifying the source of password reset requests and not adequately obscuring the email address returned in its response. As a result, an attacker can exploit this weakness to gather sensitive information about the site's users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.