API Bearer Auth [api-bearer-auth] < 20190908
unknown
[en] In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
- Affected:
- up to 20190908
- Fixed in:
- 20190908
- Disclosed:
- Sep 15, 2019
CVE-2019-16332 on NVD →
API Bearer Auth [api-bearer-auth] < 20181230
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Ricardo Sanchez in WordPress API Bearer Auth plugin (versions <= 20181229).
- Affected:
- up to 20181230
- Fixed in:
- 20181230
- Disclosed:
- Sep 6, 2019
API Bearer Auth < 20190907 - Cross-Site Scripting
medium
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
- CVSS:
- 6.1
- Affected:
- up to 20190907
- Fixed in:
- 20190907
- Disclosed:
- Sep 5, 2019
CVE-2019-16332 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database