Viewing 11 replies - 1 through 11 (of 11 total)
  • Thread Starter vinhtvu2

    (@vinhtvu2)

    I don’t know if you’ve had a chance at implementing this option, but would you consider it? We are getting bruteforce pretty hard, but since they’re actually using our user names, they’re not being blocked as quickly. Thanks!

    Plugin Author gioni

    (@gioni)

    Hi!

    Yes, it will be implemented in the next release. As of now, you can disable REST API to stop user enumeration. Do you have a reason not to do that?

    Thread Starter vinhtvu2

    (@vinhtvu2)

    I have REST disabled, but it seems WP-JSON is still available and the /wp-json/wp/v2/users/ option is still available.

    Cant wait for the new version! Thanks for all the hard work!

    Plugin Author gioni

    (@gioni)

    It must not be available. If you have disabled REST API, it is available for IPs in the White Access list only.

    Plugin Author gioni

    (@gioni)

    Resolved in 5.5

    Thread Starter vinhtvu2

    (@vinhtvu2)

    I updated one of our site to version 5.5, and tested on a device that’s off our network on a public IP range that is not on the whitelist. Still able to access the wp-json user list.

    Plugin Author gioni

    (@gioni)

    That’s weird.

    I hope you’ve checked Stop user enumeration?
    What URL do you use for tests? It should be /wp-json/wp/v2/users/

    Thread Starter vinhtvu2

    (@vinhtvu2)

    I have Stop User Enumberation checked. I tried checking disable Rest API as well but still able to get /wp-json/wp/v2/users/ on all of our sites.

    I might’ve forgot to mention that I’m using it on a multisite? Not sure if that affect it any.

    Seems like on our primary site, it’s working, or showing no user [].

    Thread Starter vinhtvu2

    (@vinhtvu2)

    Also tested on external non-whitelisted IPs.

    Plugin Author gioni

    (@gioni)

    Yes, multisite may be the cause. Do you use subfolder or subdomain installation?

    Plugin Author gioni

    (@gioni)

    @vinhtvu2 Hi! A related bug has been found and fixed in the development release 5.6.6. Check it out: https://wpcerber.com/development-version/

Viewing 11 replies - 1 through 11 (of 11 total)
  • The topic ‘wp-json user enumeration disable’ is closed to new replies.