AussieDave
24 years & still going!
- Joined
- Nov 28, 2013
- Messages
- 5,103
- Reaction score
- 3,607
Checking out my stats, raw logs etc., and found this strange URL:
hxxps://yourdomain.com/wp-json/wp/v2/users/
In layperson's terms, WP uses API's.
The above can basically be used to compromise your WP site.
I've since installed:
https://wordpress.org/plugins/disable-wp-rest-api/
This now gives anyone not logged, who attempts to run this script/code:
“rest_login_required: REST API restricted to authenticated users.”
If you have a WP site, I'd recommend installing this plugin post haste
hxxps://yourdomain.com/wp-json/wp/v2/users/
In layperson's terms, WP uses API's.
The above can basically be used to compromise your WP site.
I've since installed:
https://wordpress.org/plugins/disable-wp-rest-api/
This now gives anyone not logged, who attempts to run this script/code:
“rest_login_required: REST API restricted to authenticated users.”
If you have a WP site, I'd recommend installing this plugin post haste