Best practices to prevent users listing
-
Hello,
I’m checking my logs and I can see that there are lots of brute force with real admins from my website. So I’ve searched a bit on the internet and I found that if you use some commands on WordPress you can list all the users. This could be a weak point as they can see all my users they can see the administrators as well.
Here are some of these commands:
Method 1: Using /?author=1 Query Parameter https://[yoursite]/?author=1 Method 2: Using WordPress JSON REST Endpoints https://[yoursite]/wp-json/wp/v2/users/1
With these commands, everyone can have access to my usernames.
What is the best way to prevent that?
Thanks
Best Regards
Rodrigo
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Best practices to prevent users listing’ is closed to new replies.