← back to popular plugins
wordfence / plugin · stop-user-enumeration
Stop User Enumeration
stop-user-enumeration
total installs
50,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Stop User Enumeration <= 1.7.2 - Protection Mechanism Bypass
medium
✓ patched
cve id
CVE-2025-4302 ↗
cvss score
5.3
cwe
CWE-693: Protection Mechanism Failure
published
Jun 26, 2025
The Stop User Enumeration plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.7.2. This is due to the plugin not restricting URL encoded paths from returning user data. This makes it possible for unauthenticated attackers to enumerate WordPress users.