S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2017-18536 Scanner

CVE-2017-18536 scanner - Cross-Site Scripting (XSS) vulnerability in Stop User Enumeration plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18536
6.1
CVSS

The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Stop User Enumeration plugin for WordPress is a security plugin that prevents malicious actors from enumerating users on a WordPress site. This is helpful for preventing brute force attacks and protecting user privacy. The plugin works by redirecting any attempts to access the WordPress author archive page to the site's homepage, effectively hiding user information from potential attackers. It is a popular plugin for enhancing WordPress security and is trusted by a large number of website owners.

However, the plugin was found to have a serious vulnerability, identified as CVE-2017-18536, that allowed for cross-site scripting (XSS) attacks. This means that an attacker could inject malicious code into the WordPress site, which could be executed when a user accessed a particular page or clicked a link. This vulnerability could allow an attacker to steal login credentials and personal information, or even take full control of the site.

If this vulnerability is exploited, it can lead to various consequences that could hurt website owners. For example, an attacker could steal sensitive information from the website’s databases, hijack user accounts, or install malware onto the website. Such activities could damage the website owner’s reputation and lead to monetary losses or legal troubles.

In conclusion, vulnerabilities such as CVE-2017-18536 can cause serious harm to website owners, but there are measures that can be taken to protect against them. By following the precautions outlined above, website owners can reduce their risk of becoming victims of XSS attacks. Furthermore, website owners can benefit from the pro features of the s4e.io platform. This platform provides comprehensive information on vulnerabilities that may exist in their digital assets. With constant monitoring and analysis, website owners can ensure that their websites remain secure from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners using the Stop User Enumeration plugin should take the following precautions:

  • Update the plugin to version 1.3.8 or higher, as this version has addressed the vulnerability.
  • Regularly monitor the website for any abnormal activity or unauthorized access.
  • Use strong passwords and two-factor authentication to secure user accounts.
  • Install a firewall, web application scanner, and other security tools to enhance website protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.