WordPress Plugin Vulnerabilities

Stop User Enumeration < 1.7.3 - Protection Bypass

Description

The plugin blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Stan, Chin Siang Leow
Submitter
Stan, Chin Siang Leow
Verified
Yes

Timeline

Publicly Published
2025-06-26 (about 6 months ago)
Added
2025-06-26 (about 6 months ago)
Last Updated
2025-06-26 (about 6 months ago)

Other