Stop User Enumeration <= 1.2.4 - Security Bypass
2014-02-03 00:00
Andrew HortonStrategic Overview
Vulnerability Overview
The WordPress Stop User Enumeration Plugin for WordPress is vulnerable to Security Bypass in versions up to, and including, 1.2.4 via POST requests as the protection only functions as intended with GET requests. This makes it possible for unauthenticated attackers to perform otherwise secured actions.
Technical Analysis
REMEDIATION: Update to version 1.2.5, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C