REST API Log
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66443 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | ||
| CVE-2026-16547 | Med | 0.38 | 5.9 | 0.00 | Aug 4, 2026 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged… |
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
- risk 0.38cvss 5.9epss 0.00
The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged…