The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Be_popia_compliant | Web-x | * | 1.1.5 (including) |