wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.# CVE-2017-5487
# Installation 📝
<code>git clone https://github.com/Jhonsonwannaa/CVE-2017-5487</code>
<code>pip install -r requirements.txt</code>
# Usage 🚀
<code>python3 leak-wordpress-user.py -list urls.txt -number 10</code>
# Disclaimer ⚠️
<code>Use this tool within a legal framework.</code>
[4.0K] /data/pocs/4eede4c7875f2261592ad00ca36b61e27aa78f1a
├── [2.7K] leak-wordpress-user.py
├── [4.0K] main
│ ├── [144K] capture.png
│ ├── [3.4K] images.png
│ └── [1.7K] launch.png
├── [ 317] README.md
└── [ 43] requirements.txt
1 directory, 6 files