Stop User Enumeration plugin <1.3.9 - User Enumeration

2017-05-16 00:00
Mallory Adams

Strategic Overview

Status
Patched in 1.3.9
Affected PluginStop User Enumeration
Affected Version< 1.3.9
CVSS5.3Medium
CVECVE-2017-1000226
View all Stop User Enumeration vulnerabilities

Vulnerability Overview

The Stop User Enumeration plugin for WordPress is vulnerable to User Enumeration in versions up to, and including, 1.3.8. This is due to a flaw that was found in the REST API. This makes it possible for unauthenticated attackers to perform a POST request in the REST API allows simulating different request types. As such, attackers can perform a POST request with the “users” string in the body of the request, and tell the REST API to act like it’s received a GET request.

Technical Analysis

REMEDIATION: Update to version 1.3.9, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C