← WordPress Vulnerabilities
WordPress security by component

REST API Log

REST API Log records requests made to the WordPress REST API.

REST API Log (rest-api-log) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 5.9.

Plugin slug: rest-api-log

CVE-2026-16547: REST API Log download tokens are not bound to individual entries

REST API Log before 1.7.1 protects log downloads with a token but does not bind that token to the requested log entry or verify the requester's capability. An unauthenticated caller who obtains any valid download token can change the requested entry and retrieve other logged REST API requests and responses, potentially exposing credentials, authentication tokens or private content. The public advisory does not disclose the download route, token parameter, entry parameter or validation function.

PublishedAug 04, 2026
Known safe version1.7.1
Published vulnerabilities for rest-api-log
Safe version
Aug 04, 2026 CVE-2026-16547
REST API Log download tokens are not bound to individual entries
REST API Log before 1.7.1 protects log downloads with a token but does not bind that token to the requested log entry or verify the requester's capability. An unauthenticated caller who obtains any valid download token can change the requested entry and retrieve other logged REST API requests and responses, potentially exposing credentials, authentication tokens or private content. The public advisory does not disclose the download route, token parameter, entry parameter or validation function.
1.7.1
CVE5.9
NVDPending