Skip to main content
Vulnerability Database/CVE-2026-18365

CVE-2026-18365: zportals WordPress Information Disclosure

CVE-2026-18365 is an information disclosure vulnerability in the zportals WordPress plugin that allows subscriber-level users to access email addresses and display names of all registered users. This post covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-18365 Overview

CVE-2026-18365 is an information disclosure vulnerability in the zportals WordPress plugin versions prior to 6.4.2. The plugin exposes an AJAX action that lacks both capability checks and nonce validation. Any authenticated user with subscriber-level privileges can invoke the endpoint to enumerate the display name and email address of every registered account on the site, including administrators. The flaw is classified as [CWE-200] Information Exposure. Successful exploitation provides attackers with a curated target list for phishing, credential stuffing, and social engineering campaigns aimed at high-privilege WordPress accounts.

Critical Impact

Subscriber-level accounts can extract email addresses and display names of all users, including administrators, enabling targeted phishing and credential attacks.

Affected Products

  • zportals WordPress plugin versions prior to 6.4.2
  • WordPress sites running vulnerable zportals installations with open registration
  • Any WordPress deployment where untrusted users can obtain subscriber accounts

Discovery Timeline

  • 2026-09-23 - CVE-2026-18365 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-18365

Vulnerability Analysis

The zportals plugin registers an AJAX action handler accessible through the standard WordPress admin-ajax.php endpoint. The handler processes requests without validating the caller's WordPress capability or verifying a nonce token. Because subscriber accounts are authenticated, they satisfy the plugin's implicit authentication gate and receive the response payload.

The response enumerates all WordPress user objects and returns two sensitive fields per record: the display name and the registered email address. On sites with open registration, an unauthenticated attacker can create a subscriber account within seconds and immediately harvest the full user directory. Email addresses of administrators become the foundation for spearphishing, password reset abuse, and credential stuffing against reused passwords.

Root Cause

The root cause is missing authorization enforcement on a privileged data operation. The AJAX handler omits calls to current_user_can() for capability verification and check_ajax_referer() for nonce validation. WordPress requires plugin developers to implement both checks explicitly; the framework does not enforce them by default on custom AJAX actions. This maps to [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.

Attack Vector

Exploitation requires a valid WordPress account at any privilege tier, including subscriber. The attacker sends a crafted HTTP POST request to /wp-admin/admin-ajax.php with the vulnerable plugin's AJAX action parameter. The server responds with a JSON payload containing user records. No user interaction, elevated privileges, or complex tooling is required. Refer to the WPScan Vulnerability Report for endpoint specifics.

// No verified proof-of-concept code is published.
// Exploitation pattern: authenticated POST to admin-ajax.php
// invoking the vulnerable zportals AJAX action with no nonce.

Detection Methods for CVE-2026-18365

Indicators of Compromise

  • Unusual volume of POST requests to /wp-admin/admin-ajax.php originating from subscriber-level session cookies
  • AJAX responses larger than expected for the vulnerable zportals action, indicating bulk user enumeration
  • New subscriber account registrations followed within minutes by admin-ajax requests targeting the plugin
  • Subsequent spearphishing emails delivered to administrator addresses harvested from the site

Detection Strategies

  • Review WordPress access logs for repeated calls to the zportals AJAX action from the same authenticated session
  • Correlate new low-privilege user registrations with immediate access to plugin AJAX endpoints
  • Deploy a Web Application Firewall (WAF) rule that inspects AJAX action names against a known-vulnerable list and blocks or rate-limits unauthenticated enumeration

Monitoring Recommendations

  • Enable verbose logging on admin-ajax.php including the action parameter, source IP, and authenticated user ID
  • Alert on any single subscriber account issuing more than a small number of AJAX requests within a short window
  • Monitor outbound mail flow for phishing campaigns referencing administrator display names shortly after suspicious enumeration activity

How to Mitigate CVE-2026-18365

Immediate Actions Required

  • Update the zportals WordPress plugin to version 6.4.2 or later on all affected sites
  • Audit the WordPress user table for unrecognized subscriber accounts created before patching
  • Disable open user registration temporarily if the plugin cannot be updated immediately
  • Rotate administrator email addresses or enable multi-factor authentication (MFA) on all privileged accounts

Patch Information

The vendor addressed CVE-2026-18365 in zportals version 6.4.2. The fix introduces capability and nonce checks on the affected AJAX handler. Administrators should upgrade through the WordPress plugin dashboard or by replacing the plugin files manually. Additional detail is available in the WPScan Vulnerability Report.

Workarounds

  • Deactivate the zportals plugin until version 6.4.2 or later can be deployed
  • Restrict /wp-admin/admin-ajax.php access via WAF rules that block the specific vulnerable action name
  • Enforce MFA on all administrator accounts to reduce the impact of harvested email addresses in downstream phishing attempts
bash
# Update the zportals plugin using WP-CLI
wp plugin update zportals --version=6.4.2

# Verify installed version post-upgrade
wp plugin get zportals --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.