CVE-2024-6641

MEDIUM

WP Hardening - Security Feature Bypass

Title source: llm
STIX 2.1

Description

The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated attackers to bypass intended security restrictions and expose site usernames.

Scores

CVSS v3 5.3
EPSS 0.0038
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-185 CWE-697
Status published
Products (2)
astrasecuritysuite/WP Hardening (discontinued) < 1.2.6
getastra/wp_hardening < 1.2.7
Published Sep 18, 2024
Tracked Since Feb 18, 2026