The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any entry, which may contain sensitive data such as credentials, authentication tokens or private content.
History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pete Nelson
Pete Nelson rest Api Log
Wordpress
Wordpress wordpress
Vendors & Products Pete Nelson
Pete Nelson rest Api Log
Wordpress
Wordpress wordpress

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any entry, which may contain sensitive data such as credentials, authentication tokens or private content.
Title REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-04T06:00:13.160Z

Updated: 2026-08-04T14:05:07.818Z

Reserved: 2026-07-22T10:12:35.448Z

Link: CVE-2026-16547

cve-icon Vulnrichment

Updated: 2026-08-04T14:04:35.470Z

cve-icon NVD

No data.

cve-icon Redhat

No data.