Stop User Enumeration <= 1.3.8 - Unauthenticated Username Enumeration

2017-01-04 00:00
Glyn Wintle

Strategic Overview

Status
Patched in 1.3.9
Affected PluginStop User Enumeration
Affected Version<= 1.3.8
CVSS5.3Medium
CVECVE-2017-1000226
View all Stop User Enumeration vulnerabilities

Vulnerability Overview

The Stop User Enumeration plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 1.3.8 via the due to the REST API. This makes it possible for unauthenticated attackers to generate lists of usernames gathered from vulnerable services.

Technical Analysis

REMEDIATION: Update to version 1.3.9, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C