← WordPress Vulnerabilities
WordPress security by component

BE REST Endpoints

BE REST Endpoints (be-rest-endpoints) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.

Plugin slug: be-rest-endpoints

CVE-2026-81742: BE REST Endpoints allows unauthenticated stored script injection

BE REST Endpoints through 1.0.0 exposes widget read, create, update, and delete operations without authorization and stores widget values without sanitization. An unauthenticated attacker can save JavaScript that executes for visitors to the affected site. The authoritative export does not identify the REST route, request fields, widget store, or rendering sink.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for be-rest-endpoints
Safe version
Sep 12, 2026 CVE-2026-81742
BE REST Endpoints allows unauthenticated stored script injection
BE REST Endpoints through 1.0.0 exposes widget read, create, update, and delete operations without authorization and stores widget values without sanitization. An unauthenticated attacker can save JavaScript that executes for visitors to the affected site. The authoritative export does not identify the REST route, request fields, widget store, or rendering sink.
See mitigation notes
CVE8.8
NVDPending