CVE-2017-5487 is a vulnerability in WordPress 4.7, specifically within the REST API's user controller, that allows remote attackers to enumerate post authors. This information disclosure flaw, rated Medium severity (CVSS 5.3), permits unauthorized access to sensitive user data via a crafted wp-json/wp/v2/users request. While not listed on the KEV catalog, an exploit (EDB-41497) exists for username enumeration, and its high EPSS score indicates a significant likelihood of exploitation. Despite this, there is no evidence of active exploitation, Metasploit or Nuclei modules, or notable community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.