Re: Talsoft S.R.L. Security Advisory – WordPress User IDs and User Names Disclosure

0
57

Posted by Zerial. on May 26

Hi Veronica,

Also you can "enumerate" wordpress users using the wp-login.php. When
you enter a non-existent user wordpress returns "Invalid username" and
when you enter a valid user with any random/dummie password, wordpress
returns "Invalid Password". Now you can use brute-force to enumerate all
valid users using, for example, a name&username dictionary.

Try using https://wordpress.com/wp-login.php

Is a bug?…

Source: Re: Talsoft S.R.L. Security Advisory – WordPress User IDs and User Names Disclosure