CVE-2026-16960 UNKNOWN

CVE-2026-16960

Published: 2026-09-09

Description

The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…