WordPress Core < 4.7.1 - Information Disclosure
2017-01-11 00:00
KrogsgardStrategic Overview
StatusPatched in 3.7.17
Affected CoreWordPress 4.7
Affected Version
3.7 – 4.7 · 12 branchesCVSS4.3Medium
CVE
CVE-2017-5487Vulnerability Overview
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1 --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C