Lists all WordPress usernames through the unauthenticated REST API endpoint, exposing accounts for password brute-force attacks.
Is your app exploitable through CVE-2017-5487?