FixVibe

medium

WordPress REST API User Enumeration (CVE-2017-5487)

WordPress 4.7 before 4.7.1 exposed post-author data through the REST API. FixVibe verified active scans flag public WordPress REST user-slug exposure.

CVE-2017-5487CWE-200

Attacker Impact

CVE-2017-5487 is an information-exposure issue in WordPress 4.7 before 4.7.1. NVD describes the affected REST users controller as allowing remote attackers to obtain post-author information through the WordPress users API [S1]. WordPress's 4.7.1 security release says the REST API exposed user data for users who authored public post types and narrowed that behavior in the fix [S2].

Public author slugs can help attackers target password guessing, credential stuffing, and phishing against known accounts. This is not remote code execution or proof of account compromise by itself; the business risk depends on whether the site intentionally publishes authors, whether author slugs match login identities, and what login protections are in place.

Root Cause

The original CVE came from WordPress 4.7's REST API user listing behavior. The users controller did not properly restrict post-author listing before the 4.7.1 fix [S1]. WordPress 4.7.1 changed the behavior so only post types explicitly shown in the REST API affected the exposed author data [S2].

Concrete Fixes

  • Update WordPress Core: Upgrade to WordPress 4.7.1 or newer, preferably the current maintained release [S1][S2].
  • Review Public Author Exposure: If public author listing is not intentional, restrict unauthenticated REST users endpoint access with WordPress permissions, a maintained security plugin, or an edge rule that preserves required REST routes for the editor, plugins, and integrations.
  • Reduce Login Targeting Risk: Avoid reusing public display names or author slugs as privileged login usernames where possible, and enforce MFA, rate limits, lockouts, and login monitoring.

Covered by FixVibe

FixVibe's verified active scans flag WordPress REST users endpoints that return public user objects and slugs to unauthenticated visitors, reported as a medium-severity confirmed exposure. If the author directory is intentionally public, document that choice and keep login protections strong; otherwise restrict the exposure and rerun the verified active scan.

WordPress REST API User Enumeration (CVE-2017-5487)