Anonymous user can get user list via REST API – is it a bug or a feature?
-
Hello,
There were a lot of publications about it (but no mentions on www.remarpro.com), now I have installed 4.7 and tested myself.
Yes,
curl https://your.site.with.4.7/wp-json/wp/v2/users
or
https://your.site.with.4.7/wp-json/wp/v2/users
in a browser gives a list of users.
And the REST API enabled by default.Is it a bug or a feature?
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Anonymous user can get user list via REST API – is it a bug or a feature?’ is closed to new replies.