Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass caused by URL-encoding the REST API path /wp-json/wp/v2/users/, letting attackers bypass user enumeration restrictions, exploit requires crafted URL encoding.
id: CVE-2025-4302
info:
name: Stop User Enumeration WordPress plugin - Authentication Bypass
au
...