Title: Exposed users endpoint
Last modified: May 19, 2020

---

# Exposed users endpoint

 *  Resolved [digitalant](https://wordpress.org/support/users/digitalant/)
 * (@digitalant)
 * [6 years ago](https://wordpress.org/support/topic/exposed-users-endpoint/)
 * I had disabled unauthorized access to the users API endpoint using Wordfence 
   and it worked quite well for me. After I installed and enabled this plugin, on
   a WooCommerce website I manage, it exposed the users endpoint and allowed attackers
   to harvest usernames. I noticed a large number of requests to the users endpoint
   requesting 100 usernames in each go. The endpoint was disabled when I disabled
   this plugin. Is there a way I can disable caching for certain endpoints? It’s
   a great plugin and significantly improved the API fetches from my website but
   I can’t use it if it allows usernames to be harvested.

Viewing 1 replies (of 1 total)

 *  Plugin Author [Richard Korthuis](https://wordpress.org/support/users/rockfire/)
 * (@rockfire)
 * [5 years, 11 months ago](https://wordpress.org/support/topic/exposed-users-endpoint/#post-13059064)
 * Hi [@digitalant](https://wordpress.org/support/users/digitalant/)
 * Thank you for using our plugin! And sorry for responding this late, we have been
   quite busy lately.
 * To answer your question: Yes you can disable caching for certain endpoints, [see our FAQ](https://wordpress.org/plugins/wp-rest-cache/#can%20i%20unregister%20an%20endpoint%20so%20it%20is%20no%20longer%20cached%3F)
   for instruction on how to do so.

Viewing 1 replies (of 1 total)

The topic ‘Exposed users endpoint’ is closed to new replies.

 * ![](https://ps.w.org/wp-rest-cache/assets/icon-256x256.png?rev=3328849)
 * [WP REST Cache](https://wordpress.org/plugins/wp-rest-cache/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wp-rest-cache/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wp-rest-cache/)
 * [Active Topics](https://wordpress.org/support/plugin/wp-rest-cache/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wp-rest-cache/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wp-rest-cache/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [Richard Korthuis](https://wordpress.org/support/users/rockfire/)
 * Last activity: [5 years, 11 months ago](https://wordpress.org/support/topic/exposed-users-endpoint/#post-13059064)
 * Status: resolved