Username Extracted From RSS feeds
-
Your plugin prevents the exposure of usernames via a selectable option, “Prevent discovery of usernames through ‘/?author=N’ scans, the oEmbed API, the WordPress REST API, and WordPress XML Sitemaps”, which is great.
A wpscan of my site however found usernames via analysis of the site’s RSS feeds.
Yes, there are plenty of plugins that, and articles showing you how to, disable the default RSS feeds (e.g. https://www.wpbeginner.com/wp-tutorials/how-to-disable-rss-feeds-in-wordpress/) but isn’t this something Wordfence should also be able to do? I mean, it’s just really an extension of the option above.
Note: you wouldn’t have to mess around with WordPress actions per the article above, a simple
RewriteRule ^feed/$ - [R=400,L]
in the root .htaccess would presumably do the trick.David.
- The topic ‘Username Extracted From RSS feeds’ is closed to new replies.