Vulnerability Description
The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fullworksplugins | Stop User Enumeration | < 1.7.3 |
References
- https://wpscan.com/vulnerability/19f67d6e-4ffe-4126-ac42-fb23c5017a3eThird Party AdvisoryExploit
FAQ
What is CVE-2025-4302?
CVE-2025-4302 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.
How severe is CVE-2025-4302?
CVE-2025-4302 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-4302?
Check the references section above for vendor advisories and patch information. Affected products include: Fullworksplugins Stop User Enumeration.