The REST API exposes user data for all users who had authored a post of a public post type. The patch limits this to only post types which have specified that they should be shown within the REST API.
This vulnerability affects the following application versions:
- WordPress 4.7