PT-2024-37770 · WordPress · Wp Hardening – Fix Your Wordpress Security
Felipe Caon
·
Published
2024-09-17
·
Updated
2024-09-25
·
CVE-2024-6641
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The WP Hardening – Fix Your WordPress Security plugin versions up to, and including, 1.2.6
Description
The issue is due to the use of an incorrect regular expression within the "Stop User Enumeration" feature, making it possible for unauthenticated attackers to bypass intended security restrictions and expose site usernames.
Recommendations
For versions up to, and including, 1.2.6, update to a version later than 1.2.6 to resolve the issue.
As a temporary workaround, consider disabling the "Stop User Enumeration" feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Hardening – Fix Your Wordpress Security