Description
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
Remediation
References
Related Vulnerabilities
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)
Dolibarr Inadequate Encryption Strength Vulnerability (CVE-2017-7888)
Drupal Improper Access Control Vulnerability (CVE-2016-3162)
Serendipity URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-5474)
MyBB Improper Privilege Management Vulnerability (CVE-2018-1000503)