vendor:
Wordpress
by:
SajjadBnd
7.5
CVSS
HIGH
User Enumeration
200
CWE
Product Name: Wordpress
Affected Version From: Wordpress 5.3
Affected Version To: Wordpress 5.3
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wordpress
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04, Python 2.7
2019
WordPress < 5.3 - User Disclosure
This exploit allows an attacker to enumerate users of a Wordpress website running version 5.3 or lower. The exploit uses the /wp-json/wp/v2/users/ endpoint to retrieve a list of users from the website.
Mitigation:
Upgrade to the latest version of Wordpress