WordPress Plugin Vulnerabilities

Wordfence < 7.1.14 - Username Enumeration Prevention Bypass

Description

The plugin protection against user enumeration (ie ?author=id) could be bypassed by using an array as author parameter

Proof of Concept

Affects Plugins

Fixed in 7.1.14

References

Miscellaneous

Original Researcher
Janek Vind "waraxe"
Submitter
Ryan Dewhurst
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2018-10-02 (about 7 years ago)
Added
2018-10-18 (about 7 years ago)
Last Updated
2021-10-21 (about 4 years ago)

Other