Wordfence did not block ?author=x
-
I am using Wordfence 5.3.6 and the option “Prevent discovery of usernames through ‘?/author=N’ scans” is enabled.
However today I found a lot of 404s for urls like /?author=5 which also display the information of this user. The funny thing is that the ids 1 and 2 redirected to / while 3 and 4 exposed the user information.
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Wordfence did not block ?author=x’ is closed to new replies.