Αυτοματοποιημένη ανακάλυψη χρηστών στο WordPress
Automated user discovery in WordPress

View/ Open
Keywords
CMS ; User enumeration ; WordPressAbstract
The widespread adoption of Content Management Systems (CMS) has made these platforms a fundamental component of modern web presence, while also turning them into attractive targets for cyberattacks. Among the most common and often underestimated threats is user enumeration, which enables the identification of valid user accounts and serves as a preparatory step for more advanced attacks such as brute force and credential stuffing. This thesis focuses on WordPress, the most widely used CMS worldwide, examining both an older version (WordPress 4.7.1) and a modern version (WordPress 6.9), with the aim of analyzing and comparing the available user enumeration vectors.
To achieve this goal, a controlled laboratory environment based on virtual machines was developed, in which multiple user roles were implemented and systematic tests were conducted through REST API endpoints, content metadata, authentication error messages, HTML author attribution, and URL parameters. The results demonstrate that, despite the security improvements introduced in newer versions, user enumeration remains possible through direct or indirect mechanisms, a fact attributed to a combination of design choices at different architectural layers of the system. Within the scope of this study, mitigation techniques were applied at both the web server level (Nginx) and the WordPress application level. These techniques were experimentally evaluated and led to a substantial reduction of the attack surface without negatively affecting system functionality.

