CVE-2017-5487
MEDIUM 5.3EPSS 87.3%
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
- CVSS v3.0
- 5.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 87.30% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- medium
- Published
- 2017-01-15
- Updated
- 2024-08-05
Proof-of-concept exploits (13)
- GeunSam2/CVE-2017-54872★ · 2019-06-10
- Jhonsonwannaa/CVE-2017-54870★ · 2025-02-22
- K3ysTr0K3R/CVE-2017-5487-EXPLOIT9★ · 2023-09-27
- MRKWP/mrkwp-rest-permissions3★ · 2024-04-04
- SeasonLeague/CVE-2017-54870★ · 2023-01-29
- dream434/CVE-2017-54870★ · 2025-02-22
- mr-won/cve-2017-54870★ · 2025-03-08
- ndr-repo/CVE-2017-54870★ · 2025-05-14
- ndr-repo/PSRedTeam0★ · 2026-08-20
- patilkr/wp-CVE-2017-5487-exploit2★ · 2020-04-30
- tpdlshdmlrkfmcla/cve-2017-54870★ · 2025-03-08
- user20252228/cve-2017-54870★ · 2025-03-08
- zkhalidul/GrabberWP-CVE-2017-54870★ · 2021-11-09