CVE-2017-1000226 describes a user enumeration vulnerability in version 1.3.8 of the fullworksplugins Stop User Enumeration plugin, allowing attackers to identify valid usernames through the REST API. This medium-severity vulnerability (CVSS 5.3) can be exploited remotely with low complexity and no user interaction, potentially leading to information disclosure. While the vulnerability is not currently on the CISA KEV catalog and lacks public exploit code or significant community discussion, its presence in a security plugin is noteworthy.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.8CPE matchmatch criteria | cpe:2.3:a:fullworksplugins:stop_user_enumeration:1.3.8:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.