Unauthorized Data Exposure in Admin Safety Guard WordPress Plugin
CVE-2026-16578
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 August 2026
Badges
What is CVE-2026-16578?
The Admin Safety Guard plugin for WordPress, specifically in versions prior to 1.4.0, suffers from a critical vulnerability due to a lack of capability checks on its REST API endpoint. This oversight permits unauthenticated attackers to access sensitive information, including a comprehensive list of registered users along with their usernames, email addresses, roles, and the status of their two-factor authentication enrollment. Given this flaw, it is imperative for users of the plugin to upgrade to version 1.4.0 or later to secure their WordPress installations from potential unauthorized data exposure.
Affected Version(s)
Admin Safety Guard β Login Security, Limit Logins, 2FA & Brute Force Protection 1.2.7 < 1.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.