wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
# CVE-2017-5487
# Installation 📝
<code>git clone https://github.com/dream434/CVE-2017-5487</code>
<code>pip install -r requirements.txt</code>
# Usage 🚀
<code>python3 leak-wordpress-user.py -list urls.txt -number 10</code>
# Disclaimer ⚠️
<code>Use this tool within a legal framework.</code>
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view