CVE-2024-6641

MEDIUM

WP Hardening - Security Feature Bypass

Title source: llm

Description

The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated attackers to bypass intended security restrictions and expose site usernames.

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 56.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-697 CWE-185
Status published

Affected Products (1)

getastra/wp_hardening < 1.2.7

Timeline

Published Sep 18, 2024
Tracked Since Feb 18, 2026