CVE-2026-16149Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every registered handler's permission_callback on both the /wp/v2/users and /wp/v2/users/(?P<id>[\d]+) routes — including POST, PUT, PATCH, and DELETE handlers — with a bare closure that returns only is_user_logged_in(), completely stripping WordPress Core's original capability checks such as create_users, promote_user, edit_users, and delete_users that WP_REST_Users_Controller normally enforces. This makes it possible for authenticated attackers with Subscriber-level access and above to create new Administrator accounts by sending POST request to /wp/v2/users with administrator role, or to reset an existing Administrator's password by issuing a PUT/POST request to /wp/v2/users/<id>. Because the block_user_enum option defaults to enabled, no special plugin configuration is required — the overwrite is active on every request as soon as the plugin is installed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-08-23); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-08-23: 4Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-23: 3Technical Details · 2026-08-24: 108-2308-24
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-234
Disclosure4
2026-08-241
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-16149 The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the pl… https://www.cve.org/CVERecord?id=CVE-2026-16149

    Post summary

    CVE-2026-16149 is disclosed as a missing authorization flaw in the Security Hardener WordPress plugin, affecting all versions up to 2.4.4.

    02000763
    58.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-16149 - Missing Authorization in WordPress Security Hardener plugin (<=2.4.4). Bypasses REST API protections. CVSS 8.8. Monitor for patch now. #CVE #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-16149 #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany

    Post summary

    The post announces a CVE-2026-16149 vulnerability in the WordPress Security Hardener plugin, highlights missing authorization and REST API bypass, and urges users to wait for a patch.

    0001049
    1.0K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    WordPress users: Security Hardener plugin vulnerable to missing authorization (CVE-2026-16149, CVSS 8.8) in versions up to 2.4.4. Update promptly. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/Tx1PAMgch7

    Post summary

    WordPress Security Hardener plugin up to version 2.4.4 suffers a missing authorization flaw (CVE-2026-16149, CVSS 8.8); users are urged to update immediately.

    0000036
    93 followersView on X
  • LoreleiWeb@LoreleiWeb
    Disclosure

    🆕👉 Security Hardener https://wpdeeply.com/security-hardener-2-4-4-subscriber-privilege-escalation-rest-users/ #loreleiweb Wordfence Intelligence published CVE-2026-16149 on August 22, 2026 for Security Hardener, a WordPress hardening plugin with 200+ active installations. The flaw is serious because it affects the plugin’s own user-enume… https://t.co/pHaMjrmp3E

    Post summary

    Wordfence Intelligence released CVE‑2026‑16149 for the Security Hardener plugin, noting a serious flaw related to the plugin’s own user enumeration, but the post lacks detailed technical or exploit information.

    00000174
    85.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16149 The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the pl… https://www.cve.org/CVERecord?id=CVE-2026-16149 ----- Traducción: CVE-2026-16149 El … http://infoflow.cloud`

    Post summary

    The post discloses CVE-2026-16149 for the Security Hardener WordPress plugin, noting a missing authorization flaw in versions up to 2.4.4, but does not provide PoC, exploit, or patch information.

    0000039
    102 followersView on X

Explore more