Your WordPress REST API Is Leaking User Data — Here’s the Fix
The WordPress REST API exposes your user list at /wp-json/wp/v2/users — no login required. Here’s how to restrict it without breaking your site.
The WordPress REST API exposes your user list at /wp-json/wp/v2/users — no login required. Here’s how to restrict it without breaking your site.