CVE-2017-5487

MEDIUM

Wordpress < 4.7 - Information Disclosure

Title source: rule

Description

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

Exploits (12)

nomisec WORKING POC 8 stars
by K3ysTr0K3R · poc
https://github.com/K3ysTr0K3R/CVE-2017-5487-EXPLOIT
nomisec WORKING POC 2 stars
by GeunSam2 · poc
https://github.com/GeunSam2/CVE-2017-5487
nomisec SCANNER 2 stars
by patilkr · poc
https://github.com/patilkr/wp-CVE-2017-5487-exploit
nomisec WORKING POC 1 stars
by R3K1NG · poc
https://github.com/R3K1NG/wpUsersScan
nomisec WORKING POC
by teambugsbunny · poc
https://github.com/teambugsbunny/wpUsersScan
nomisec SCANNER
by SeasonLeague · poc
https://github.com/SeasonLeague/CVE-2017-5487
nomisec WORKING POC
by dream434 · poc
https://github.com/dream434/CVE-2017-5487
nomisec WORKING POC
by ndr-repo · poc
https://github.com/ndr-repo/CVE-2017-5487
nomisec WRITEUP
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/cve-2017-5487
nomisec SCANNER
by zkhalidul · poc
https://github.com/zkhalidul/GrabberWP-CVE-2017-5487
github WORKING POC
by Anzinius · pythonpoc
https://github.com/Anzinius/CVE-PoC-Collection/tree/main/cve-2017-5487
exploitdb SCANNER
by Dctor · phpwebappsphp
https://www.exploit-db.com/exploits/41497

Scores

CVSS v3 5.3
EPSS 0.9250
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (2)

wordpress/wordpress < 4.7
n/a/n/a

Timeline

Published Jan 15, 2017
Tracked Since Feb 18, 2026