Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21758 | The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path. |
Fri, 23 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fullworksplugins
Fullworksplugins stop User Enumeration |
|
| CPEs | cpe:2.3:a:fullworksplugins:stop_user_enumeration:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Fullworks
Fullworks stop User Enumeration |
Fullworksplugins
Fullworksplugins stop User Enumeration |
Fri, 02 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fullworks
Fullworks stop User Enumeration |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:fullworks:stop_user_enumeration:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Fullworks
Fullworks stop User Enumeration |
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 17 Jul 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path. | |
| Title | Stop User Enumeration < 1.7.3 - Protection Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-07-17T13:36:10.039Z
Reserved: 2025-05-05T12:24:36.389Z
Link: CVE-2025-4302
Updated: 2025-07-17T13:36:04.939Z
Status : Analyzed
Published: 2025-07-17T08:15:27.530
Modified: 2026-01-23T19:30:49.850
Link: CVE-2025-4302
No data.
OpenCVE Enrichment
No data.
EUVD