CVE-2025-4302: Stop User Enumeration < 1.7.3 - Protection Bypass
Published Jul 17, 2025
·Updated
The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.
Affected Software
2 affected components
Stop User Enumeration Stop User Enumeration WordPress plugin<1.7.3
Fullworksplugins Stop User Enumeration Wordpress<1.7.3
Event History
Jul 17, 2025
CVE Published
via MITRE·07:37 AM
Data Sourced
via MITRE·07:37 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4302?
CVE-2025-4302 has a high severity due to its potential to allow unauthorized users to access sensitive user information.
2
How do I fix CVE-2025-4302?
To fix CVE-2025-4302, update the Stop User Enumeration WordPress plugin to version 1.7.3 or later.
3
What does CVE-2025-4302 affect?
CVE-2025-4302 affects the Stop User Enumeration WordPress plugin versions prior to 1.7.3.
4
What type of vulnerability is CVE-2025-4302?
CVE-2025-4302 is a vulnerability that allows users to bypass access controls to the WordPress REST API.
5
Who is impacted by CVE-2025-4302?
Users of the Stop User Enumeration WordPress plugin on versions before 1.7.3 are impacted by CVE-2025-4302.