plugin

Json Rest Api Vulnerabilities

3 known security issues reported for the Json Rest Api WordPress plugin. Most recent disclosed Aug 14, 2015.

2 high 1 medium

Running Json Rest Api on your site? Check whether your installed version is affected.

Scan your site free

WP REST API <= 1.2.2 - Cross-Site Scripting

medium

The WP REST API plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Aug 14, 2015

WP REST API (WP API) < 1.2.1 - Sensitive Information Disclosure

high

The WP REST API (WP API) plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.2. This could allow attackers to extract sensitive user or configuration data.

CVSS:
7.5
Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Apr 9, 2015

JSON REST API <= 1.1 - Potential Cross-Site Request Forgery Bypass

high

The JSON REST API plugin for WordPress is possibly vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1 due to a potential SOP bypass. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to conduct JSON Flash attacks via a forged request g...

CVSS:
8.8
Affected:
up to 1.1
Fixed in:
1.1.1
Disclosed:
Jul 10, 2014

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database