Stop User Enumeration

Stop User Enumeration is a security plugin that prevents hackers from scanning a website for user login names, which is often a precursor to brute-force password attacks. The plugin blocks user enumeration requests by GET or POST, logs IP addresses launching attacks, and can be used in conjunction with fail2ban to block attempts at the firewall. It also restricts and logs API calls that obtain user data without logging in and can remove author information from the sitemap and oEmbed API call. The plugin is compatible with PHP 8.0.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Access violation vulnerability in Stop User Enumeration 1.2.4

    Fixed

    The WordPress Stop User Enumeration Plugin for WordPress is vulnerable to a security bypass in versions up to 1.2.4. This means that unauthenticated attackers can perform actions that should be secur...

    Read More
  • Access violation vulnerability in Stop User Enumeration 1.3.4

    Fixed

    The Stop User Enumeration plugin for WordPress is not secure in versions up to and including 1.3.4. This means that unauthenticated attackers can figure out the list of valid users, which can then be...

    Read More
  • Input validation vulnerability in Stop User Enumeration 1.3.8

    Fixed

    The Stop User Enumeration plugin for WordPress is not secure in versions up to 1.3.7. This means that it is possible for someone to trick the plugin into letting them add malicious code to a website. ...

    Read More
  • Access violation vulnerability in Stop User Enumeration 1.3.8

    Fixed

    The Stop User Enumeration plugin for WordPress is not secure in versions up to 1.3.8. This means that anyone who is not logged in can make a list of usernames by exploiting the vulnerability in the R...

    Read More
  • Access violation vulnerability in Stop User Enumeration 1.3.9

    Fixed

    The Stop User Enumeration plugin for WordPress has a security flaw that affects versions up to and including 1.3.8. This means that an unauthenticated attacker can use a POST request to the REST API t...

    Read More
  • Access violation vulnerability in Freemius SDK (134 components affected)

    Fixed

    The Freemius SDK is a plugin used in WordPress websites. A security vulnerability was discovered in versions up to 2.2.3 which could allow users with subscriber-level permissions to change settings an...

    Read More