Junglewise Threat Intelligence

CVE-2026-16149: Security Hardener Missing Authorization in REST API endpoints

CVE-2026-16149 · Severity: high · CVSS 8.8 · Published 2026-08-23

Executive brief

The Security Hardener plugin for WordPress, used by site administrators to restrict unauthorized user enumeration, contains a critical flaw that actually strips away WordPress's built-in permission controls on user management endpoints. An attacker with even the lowest user role (Subscriber) can exploit this to create new Administrator accounts or reset existing administrator passwords, effectively taking over the WordPress site. The vulnerability is enabled by default and requires no special configuration.

Technical details

The vulnerability is a missing authorization flaw (CWE-862) in the Security Hardener plugin's user-enumeration protection feature. The secure_user_endpoints() function hooks the rest_endpoints filter and overwrites the permission_callback on WordPress REST API routes /wp/v2/users and /wp/v2/users/{id} with a closure that checks only is_user_logged_in(), completely removing WordPress Core's native capability checks (create_users, promote_user, edit_users, delete_users). This permits authenticated attackers with Subscriber-level access and above to send POST requests to /wp/v2/users with an administrator role parameter to create new admin accounts, or PUT/PATCH requests to /wp/v2/users/{id} to reset existing administrator passwords. The block_user_enum option defaults to enabled, so the vulnerability is active immediately upon plugin installation without requiring additional configuration. Patches are available in versions after 2.4.4.

Affected products

  • wpwhitesecurity Security Hardener up to and including 2.4.4

Timeline

  • 2026-08-23: disclosed

References