CVE-2017-5487Active Exploitation(wordpress / wordpress)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch wordpress wordpress systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wordpress

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • False Positive: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-31); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wordpress

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-31: 1Mentions · 2026-08-21: 1Active Exploitation · 2026-01-31: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 101-3108-21
Signal classification2 categories
Active Exploitation
150.0%
False Positive
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-311
Active Exploitation1
2026-08-211
False Positive1
Full discourse2 posts
  • AHosting.net@ahostingdotnet
    False Positive

    If a scanner sent you here citing CVE-2017-5487: that was fixed in WordPress 4.7.1, in January 2017. 4.7.0 returned authors of any public post type. 4.7.1 narrowed it to post types that opt into REST. What you are seeing on 7.0 today is the intended behavior, not the old flaw.

    Post summary

    The post clarifies that CVE‑2017‑5487 was fixed in WordPress 4.7.1 and that the behavior observed on version 7.0 is intended, debunking concerns about an active flaw.

    1000016
    982 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2017-5487 — Google LLC Visit -- https://cti.loginsoft.com/ip/34.19.127.197 #Loginsoft #Cytellite #Cybersecurity #CVE20175487 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/krO4npn5Xy

    Post summary

    Cytellite reports recent detection of activity exploiting CVE‑2017‑5487, indicating that the vulnerability is actively leveraged in the wild.

    00010142
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwordpresswordpress---

Explore more