WordPress Core, the software used to create websites, has a weakness in versions 4.7.0 to 6.3.1 which can expose sensitive information. If someone searches for a user, the search results may include the user’s email address, even if that person shouldn’t be able to see it. This could allow unauthenticated attackers to guess or confirm email addresses of users with published posts or pages on the website.