The Stop User Enumeration plugin for WordPress is not secure in versions up to 1.3.8. This means that anyone who is not logged in can make a list of usernames by exploiting the vulnerability in the REST API.
Documentation: Home / Vulnerabilities / Access violation vulnerability in Stop User Enumeration 1.3.8
The Stop User Enumeration plugin for WordPress is not secure in versions up to 1.3.8. This means that anyone who is not logged in can make a list of usernames by exploiting the vulnerability in the REST API.
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.
© Really Simple Plugins
CoC 70461155
Kalmarweg 14-5
9723 JG, Groningen (NL)