Security Advisory

CVE-2025-4302

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-17 07:37:11
Last updated 2025-07-17 13:36:10
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.