PT-2025-29904 · WordPress · Stop User Enumeration

Published

2025-07-17

·

Updated

2026-01-02

·

CVE-2025-4302

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stop User Enumeration WordPress plugin versions prior to 1.7.3
Description The Stop User Enumeration WordPress plugin blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. This protection can be bypassed by URL-encoding the API path.
Recommendations Update Stop User Enumeration WordPress plugin to version 1.7.3 or later.

Exploit

Fix

Related Identifiers

CVE-2025-4302

Affected Products

Stop User Enumeration