Medium severity5.3NVD Advisory· Published Sep 18, 2024· Updated Jun 17, 2026
CVE-2024-6641
CVE-2024-6641
Description
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated attackers to bypass intended security restrictions and expose site usernames.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=1.2.6+ 1 more
- (no CPE)range: <=1.2.6
- (no CPE)
- astrasecuritysuite/WP Hardening (discontinued)v5Range: 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.