[wp-trac] [WordPress Trac] #44449: WP_REST_Users_Controller->get_item_permissions_check() should return permission error even if user does not exist

WordPress Trac noreply at wordpress.org
Mon Jun 25 07:53:11 UTC 2018


#44449: WP_REST_Users_Controller->get_item_permissions_check() should return
permission error even if user does not exist
--------------------------+------------------------------
 Reporter:  Ste_95        |       Owner:  (none)
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  REST API      |     Version:
 Severity:  normal        |  Resolution:
 Keywords:  close         |     Focuses:
--------------------------+------------------------------
Changes (by swissspidy):

 * keywords:   => close
 * focuses:  rest-api =>
 * component:  Security => REST API


Comment:

 Disclosure of usernames and user IDs is
 [https://make.wordpress.org/core/handbook/testing/reporting-security-
 vulnerabilities/#why-are-disclosures-of-usernames-or-user-ids-not-a
 -security-issue not a security issue]. If you want to get a list of
 usernames you could just try logging in or use the password reset form to
 achieve the same.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/44449#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list