This plugin usually does the trick (I disable some other stuff as well separately like author sitemaps). But on one site, I can still enumerate one of 4 users using WPScan like so :
[i] User(s) Identified: [+] firstname-lastname | Found By: Author Posts - Author Pattern (Passive Detection)
This isn’t the real name of course but it did detect a user with it’s real firstname, hyphen, lastname. This doesn’t correspond to a login nor nickname but does to the real person’s name. Is the plugin supposed to catch this or not?
- The topic ‘User Found By: Author Posts – Author Pattern’ is closed to new replies.