User enumeration
WordPress can leak a list of its usernames through its REST API, handing attackers half of what they need to break in.
What it is
To log in, an attacker needs a username and a password. WordPress's REST API can, by default, return a list of the site's users — including their login names — to anyone who asks, at a predictable address like /wp-json/wp/v2/users.
That turns a private detail into a public one, and gives attackers a confirmed list of accounts to target.
Why it matters
Once an attacker knows valid usernames, a brute-force or credential-stuffing attack becomes far more effective — they're no longer guessing who exists, only the passwords. Combined with a login page that has no rate limiting, exposed usernames are a serious step towards account takeover.
How Pentrawl checks it
Pentrawl requests the WordPress REST API users endpoint and checks whether it returns user data to an unauthenticated visitor. If usernames are exposed, it's flagged as an issue.
How to fix it
Block unauthenticated access to the users endpoint. Most WordPress security plugins offer this with a single setting, or it can be restricted in your theme or server configuration.
Use a security plugin (or a filter) to restrict /wp-json/wp/v2/users to authenticated requests.