WordPress Plugin Vulnerabilities

BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation

Description

The plugin does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
Unauthenticated users can also create and delete widgets, and read the content of widgets the site owner has removed from every sidebar.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other