← back to popular plugins
wordfence / plugin · stop-user-enumeration

Stop User Enumeration

stop-user-enumeration
total installs
50,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Stop User Enumeration <= 1.7.2 - Protection Mechanism Bypass
medium ✓ patched
cvss score 5.3
cwe CWE-693: Protection Mechanism Failure
published Jun 26, 2025
The Stop User Enumeration plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.7.2. This is due to the plugin not restricting URL encoded paths from returning user data. This makes it possible for unauthenticated attackers to enumerate WordPress users.