Stop User Enumeration <= 1.7.2 - Protection Mechanism Bypass

2025-06-26 00:00
Stan

Strategic Overview

Status
Patched in 1.7.3
Affected PluginStop User Enumeration
Affected Version<= 1.7.2
CVSS5.3Medium
CVECVE-2025-4302
View all Stop User Enumeration vulnerabilities

Vulnerability Overview

The Stop User Enumeration plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.7.2. This is due to the plugin not restricting URL encoded paths from returning user data. This makes it possible for unauthenticated attackers to enumerate WordPress users.

Technical Analysis

REMEDIATION: Update to version 1.7.3, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C