VYPR

Security Hardener

by WordPress

CVEs (1)

  • CVE-2026-16149HigAug 23, 2026
    risk 0.50cvss 8.8epss

    The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via…