Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-4302 | 1 Fullworks | 1 Stop User Enumeration | 2026-01-02 | 5.3 Medium |
| The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path. | ||||
| CVE-2017-1000226 | 1 Fullworks | 1 Stop User Enumeration | 2025-04-20 | N/A |
| Stop User Enumeration 1.3.8 allows user enumeration via the REST API | ||||
| CVE-2021-24767 | 1 Fullworks | 1 Redirect 404 Error Page To Homepage Or Custom Page With Logs | 2024-11-21 | 6.5 Medium |
| The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack | ||||
| CVE-2017-18536 | 1 Fullworks | 1 Stop User Enumeration | 2024-11-21 | N/A |
| The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS. | ||||
Page 1 of 1.