• Resolved nimrod54

    (@nimrod54)


    Hi,

    thank you for the nice plugin, I’m using Cerber since years without any problem.

    I set up a new website, installed WP 5 and Cerber 7.9.3. I’m also using Elementor page builder. I checked ‘Disable Rest API’ for both “Block access …” and “Allow Rest API for logged in users”. Every time I create a new page I get an entry “Request to REST API denied” in Cerber activities and URL: domain.name/wp-json/wp/v2/users/
    I read https://wpcerber.com/restrict-access-to-wordpress-rest-api/, added ‘elementor’ and ‘WP’, but the event entry continues to appear.

Viewing 6 replies - 1 through 6 (of 6 total)
  • Thread Starter nimrod54

    (@nimrod54)

    Hi,
    I believe I found what has caused the issue. I disabled ‘Stop user enumeration’ and the problem disappeared

    Plugin Author gioni

    (@gioni)

    Why would Elementor page builder need the list of website users? Maybe it’s a breach builder? ??

    Thread Starter nimrod54

    (@nimrod54)

    Hi,
    unfortunately I’m an unexperiended WP user without a broad knowledgebase.

    Just a guess: Elementor has Role Manager, that could be the reason.
    And no, it’s not a breach builder ?? It’s a very popular page builder and it’s actually very well built.

    Thread Starter nimrod54

    (@nimrod54)

    Hi guys,
    thank you.
    As written earlier, disabeling ‘Stop user enumeration’ resolved the issue
    best regards

    Plugin Author gioni

    (@gioni)

    I don’t like the idea of enabling user enumeration and providing unlimited access to user data. WordPress itself is “very popular” too, but it had/has thousands of vulnerabilities and design flaws: https://wpvulndb.com/wordpresses

    Anyway, in one of the next versions of the plugin, there will be a solution.

    @bugnumber9

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘rest api name space’ is closed to new replies.