Unauthorized Data Export Vulnerability in Latest Registered Users Plugin for WordPress
CVE-2025-13493
What is CVE-2025-13493?
The Latest Registered Users plugin for WordPress has a security flaw that enables unauthorized data export. This vulnerability arises from a lack of proper authorization checks and nonce validation within the rnd_handle_form_submit function, which is associated with both admin_post_my_simple_form and admin_post_nopriv_my_simple_form actions. As a result, attackers can exploit this weakness to export comprehensive user details, excluding sensitive information such as passwords and tokens, in CSV format through the 'action' parameter. This significant oversight places user privacy and data security at risk, making it essential for site administrators to address the vulnerability promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Latest Registered Users * <= 1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved