CVE Vulnerabilities

CVE-2025-4302

Published: Jul 17, 2025 | Modified: Jan 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

Affected Software

NameVendorStart VersionEnd Version
Stop_user_enumerationFullworksplugins*1.7.3 (excluding)

References