security / cms & plugins / user enumeration
CMS & plugins

User enumeration

WordPress can leak a list of its usernames through its REST API, handing attackers half of what they need to break in.

Severity if missing
High
Category
CMS & plugins
Standard
OWASP

What it is

To log in, an attacker needs a username and a password. WordPress's REST API can, by default, return a list of the site's users — including their login names — to anyone who asks, at a predictable address like /wp-json/wp/v2/users.

That turns a private detail into a public one, and gives attackers a confirmed list of accounts to target.

Why it matters

Once an attacker knows valid usernames, a brute-force or credential-stuffing attack becomes far more effective — they're no longer guessing who exists, only the passwords. Combined with a login page that has no rate limiting, exposed usernames are a serious step towards account takeover.

The risk
Exposed usernames give attackers confirmed targets for password attacks, significantly increasing the chance of a successful break-in.

How Pentrawl checks it

Pentrawl requests the WordPress REST API users endpoint and checks whether it returns user data to an unauthenticated visitor. If usernames are exposed, it's flagged as an issue.

How to fix it

Block unauthenticated access to the users endpoint. Most WordPress security plugins offer this with a single setting, or it can be restricted in your theme or server configuration.

Recommended
Use a security plugin (or a filter) to restrict /wp-json/wp/v2/users to authenticated requests.

Related checks

Check your domain's User enumeration in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →