Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin Reveal Email Addresses to Unauthenticated Users

MINI-jxjw-9mjv-p9q7
Summary

A vulnerability in a WordPress plugin exposes email addresses of users to anyone who can access a website. This means that if an attacker can visit your website, they can see the email addresses of your users. To protect your users, update the plugin to the latest version or remove it if possible.

What to do
  • Update openclaw to version 2026.3.7-r0.
Affected software
VendorProductAffected versionsFix available
– openclaw <= 2026.3.7-r0 2026.3.7-r0
Original title
MINI-jxjw-9mjv-p9q7
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026