HomeHow ToWordPress: Disable REST API

WordPress: Disable REST API

The latest version of WordPress comes with new features in the REST API that can be leveraged by plugins, applications, services, or the WordPress Core itself.

However, many times, some of the new features added by Automattic developers are not used by all administrators of the popular blogging platform. For example, at SecNews we do not use Emojis and XML-RPC.

The new REST API functionality, for example, can be used by anyone on the WordPress user list.WordPress

This alone is not enough to give access to site functions, but it allows a malicious user to discover all the usernames and, with brute force attacks, try to guess the passwords they use. Of course, they can also use social engineering to collect more data.

It should be noted that the new API doesn't expose anything more than usernames that are already available elsewhere on the site anyway. It simply displays a list of all WordPress user accounts.

To see all user accounts on any site running WordPress 4.7 you should go to:

https://domain_name/wp-json/wp/v2/users

Let's now see how you can block access to this information. You can do this by installing a plugin or by adding code to functions.php located in the folder containing the theme you are using.

The plugin is called Disable REST API and as its name suggests it will disable the REST API by displaying an “Unauthorized Access” message to anonymous requests requesting data from the REST API.

Let's also look at the code you can add to functions.php:

//*Disable REST API $current_WP_version = get_bloginfo('version'); if ( version_compare( $current_WP_version, '4.7', '>=' ) ) { Force_Auth_Error(); } else { Disable_Via_Filters(); } function Force_Auth_Error() { add_filter( 'rest_authentication_errors', 'only_allow_logged_in_rest_access' ); } function Disable_Via_Filters() { // Filters for WP-API version 1.x add_filter( 'json_enabled', '__return_false' ); add_filter( 'json_jsonp_enabled', '__return_false' ); // Filters for WP-API version 2.x add_filter( 'rest_enabled', '__return_false' ); add_filter( 'rest_jsonp_enabled', '__return_false' ); // Remove REST API info from head and headers remove_action( 'xmlrpc_rsd_apis', 'rest_output_rsd' ); remove_action( 'wp_head', 'rest_output_link_wp_head', 10 ); remove_action( 'template_redirect', 'rest_output_link_header', 11 ); } function only_allow_logged_in_rest_access( $access ) { if( ! is_user_logged_in() ) { return new WP_Error( 'rest_cannot_access', __( 'REST API is NOT for YOU! Sorry pal.', 'disable-json-api' ), array( 'status' => rest_authorization_required_code() ) ); } return $access; }
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS