Unauthorized Data Export Vulnerability in Latest Registered Users Plugin for WordPress
CVE-2025-13493

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 January 2026

What is CVE-2025-13493?

The Latest Registered Users plugin for WordPress has a security flaw that enables unauthorized data export. This vulnerability arises from a lack of proper authorization checks and nonce validation within the rnd_handle_form_submit function, which is associated with both admin_post_my_simple_form and admin_post_nopriv_my_simple_form actions. As a result, attackers can exploit this weakness to export comprehensive user details, excluding sensitive information such as passwords and tokens, in CSV format through the 'action' parameter. This significant oversight places user privacy and data security at risk, making it essential for site administrators to address the vulnerability promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Latest Registered Users * <= 1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhirup Konwar
.