All posts
December 2016·5 min read

What WordPress's REST API means for security

The WordPress REST API is now enabled by default for every site. It enables powerful new development possibilities — and exposes new endpoints that weren't there before. Here's what to understand.

What the REST API is

A REST API is an interface that allows software to interact with WordPress programmatically — reading and writing posts, users, comments, and other content via standardised HTTP requests rather than through the WordPress admin interface. It's what allows external applications to integrate with WordPress, mobile apps to consume WordPress content, and JavaScript front-ends to interact with WordPress as a backend.

The WordPress REST API was introduced in stages: the infrastructure arrived in WordPress 4.4 (December 2015), and the content endpoints — the parts that expose posts, pages, and users — were added to core in WordPress 4.7 (December 2016). With 4.7, the API is active by default on every WordPress installation.

What's now publicly accessible

By default, the WordPress REST API exposes several endpoints that anyone can query without authentication. The most significant from a security standpoint:

  • /wp-json/wp/v2/users — returns a list of WordPress users including their display names, slugs, and user IDs. This is published content in WordPress's model, but it means your administrator usernames are now enumerable via a simple HTTP request.
  • /wp-json/wp/v2/posts — returns published posts, similar to what's already publicly visible but in a machine-readable format.
  • /wp-json/ — the root endpoint exposes information about your WordPress installation including what namespaces and endpoints are registered, which can reveal installed plugins that register their own API routes.

The user enumeration issue

The ability to enumerate WordPress usernames via the REST API is the most immediately relevant security concern for most sites. Previously, attackers used methods like author archive pages and login error messages to discover usernames. The REST API makes it significantly more straightforward.

Combined with brute-force tools, knowing valid usernames reduces the problem to guessing passwords only. This is a real increase in attack surface for sites that haven't already addressed login security.

How to respond

If your site doesn't use the REST API for any functionality, you can disable it entirely. Several security plugins offer this option, or it can be done with a small code snippet in your theme's functions.php. This removes the attack surface completely.

If you're using a theme or plugin that depends on the REST API (some page builders and Gutenberg-dependent features use it), disabling it entirely will break things. In that case, consider:

  • Restricting the users endpoint to require authentication, so usernames aren't publicly enumerable
  • Ensuring your login has server-level rate limiting in place, so even with known usernames, brute-force attempts are blocked
  • Using display names that don't match login usernames for administrator accounts

Looking ahead

The REST API is the foundation of where WordPress development is heading. Future features — including the block editor coming in a future release — depend on it. Understanding its security implications now, rather than after something goes wrong, is the right approach.

The API itself isn't insecure — it's a well-designed, standards-compliant interface. The security considerations are in the default configuration choices and in how it changes the site's publicly exposed surface area.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.