CVE-2017-1000226: Infoleak
Published Nov 17, 2017
·Updated
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
Affected Software
2 affected components
Fullworks Stop User Enumeration Wordpress=1.3.8
Fullworksplugins Stop User Enumeration Wordpress=1.3.8
Event History
Nov 17, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-1000226?
CVE-2017-1000226 has a medium severity rating due to its potential to facilitate user enumeration attacks.
2
How do I fix CVE-2017-1000226?
To fix CVE-2017-1000226, update the Stop User Enumeration plugin to the latest version available.
3
What does CVE-2017-1000226 affect?
CVE-2017-1000226 affects Stop User Enumeration version 1.3.8 for WordPress.
4
How does CVE-2017-1000226 enable user enumeration?
CVE-2017-1000226 allows user enumeration through the REST API, making it easier for attackers to identify valid usernames.
5
Is there a workaround for CVE-2017-1000226 if I cannot update?
A potential workaround for CVE-2017-1000226 is to disable the REST API for your WordPress site, though updating is recommended.