CVE-2025-13660 | rcatheme Guest Support Plugin up to 1.2.3 on WordPress AJAX Endpoint guest_support_handler Request information disclosure
A vulnerability marked as problematic has been reported in rcatheme Guest Support Plugin up to 1.2.3 on WordPress. This affects the function guest_support_handler of the component AJAX Endpoint. This manipulation of the argument Request with the input get_users causes information disclosure.
This vulnerability is handled as CVE-2025-13660. The attack can be initiated remotely. There is not any exploit available.