Wordpress users Disclosure

Disclosed: 2025-02-12 17:00:44 By karimtantawy To autodesk
Critical
Vulnerability Details
we can see all the WordPress users/author with some of their information. Which can even be Personal information of employees/author. The file author-sitemap.xml at:https://www.payapps.com/author-sitemap.xml is enabled and this give the attacker many users names and emails like: {F4036174} ## Impact Malicious people could collect the usernames disclosed (and the admin user) and be focused throughout BF attack (as the usernames are now known), making it less harder to penetrate your systems.
Actions
View on HackerOne
Report Stats
  • Report ID: 2981756
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report