WordPress security by component
BE REST Endpoints
BE REST Endpoints (be-rest-endpoints) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
be-rest-endpointsLatest vulnerability
CVE-2026-81742: BE REST Endpoints allows unauthenticated stored script injection
BE REST Endpoints through 1.0.0 exposes widget read, create, update, and delete operations without authorization and stores widget values without sanitization. An unauthenticated attacker can save JavaScript that executes for visitors to the affected site. The authoritative export does not identify the REST route, request fields, widget store, or rendering sink.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-81742
BE REST Endpoints allows unauthenticated stored script injection
BE REST Endpoints through 1.0.0 exposes widget read, create, update, and delete operations without authorization and stores widget values without sanitization. An unauthenticated attacker can save JavaScript that executes for visitors to the affected site. The authoritative export does not identify the REST route, request fields, widget store, or rendering sink.
|
See mitigation notes |
CVE8.8
NVDPending
|