All verified exploits

CVE-2017-5487 REST API User Enumeration

Deterministic low WordPress Added cve-verified-cve-2017-5487

Lists all WordPress usernames through the unauthenticated REST API endpoint, exposing accounts for password brute-force attacks.

Related WordPress exploits

Is your app exploitable through CVE-2017-5487?

Scan your domain free