Open API For Username enumeration
Low
W
WordPress
Submitted None
Actions:
Reported by
sameerphad72
Vulnerability Details
Technical details and impact analysis
We Can do username enumeration,
Reproduce:
1. Go any wordpress site.
#2.www.site.com/?author=1 (type ?author=1 at end of site)
3. You will get www.site.com/author/admin (now, admin is username of login panel of that site)
Thanks,
Sameer Phad
## Impact
-
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable