CVE-2026-16578
Received Received - Intake

Unauthenticated User Enumeration in Admin Safety Guard WordPress Plugin

Vulnerability report for CVE-2026-16578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The Admin Safety Guard β€” Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles, and two-factor authentication enrollment status.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
admin_safety_guard wordpress_plugin to 1.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Admin Safety Guard WordPress plugin before version 1.4.0 has a vulnerability where an unauthenticated REST API endpoint exposes sensitive user data. The endpoint /2fa/app/users lacks capability checks, allowing attackers to retrieve usernames, email addresses, roles, and two-factor authentication status of all registered users.

Detection Guidance

To detect this vulnerability, check if the WordPress plugin Admin Safety Guard is installed and if its version is below 1.4.0. You can verify the installed version via the WordPress admin panel or by inspecting the plugin files. Additionally, attempt to access the REST API endpoint /2fa/app/users without authentication to see if it returns user data.

Impact Analysis

This vulnerability allows attackers to gather detailed user information without authentication. This could lead to targeted phishing attacks, identity theft, or unauthorized access to accounts if combined with other exploits. Users of the affected plugin versions are at risk of data exposure.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized disclosure of personal and sensitive user data. Organizations using the affected plugin may face compliance violations, legal penalties, and reputational damage for failing to protect user information.

Mitigation Strategies

Immediately update the Admin Safety Guard plugin to version 1.4.0 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Ensure all WordPress installations are running the latest secure versions of all plugins and themes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart