Stop User Enumeration <= 1.7.2 - Protection Mechanism Bypass
2025-06-26 00:00
StanStrategic Overview
StatusPatched in 1.7.3
Affected PluginStop User Enumeration
Affected Version
<= 1.7.2CVSS5.3Medium
CVE
CVE-2025-4302Vulnerability Overview
The Stop User Enumeration plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.7.2. This is due to the plugin not restricting URL encoded paths from returning user data. This makes it possible for unauthenticated attackers to enumerate WordPress users.
Technical Analysis
REMEDIATION: Update to version 1.7.3, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C