WordPress REST API Authentication

The WordPress REST API Authentication plugin from MiniOrange offers protection for WordPress REST API endpoints from public access using various authentication methods, including API Key, JWT, Basic, OAuth 2.0, and third-party OAuth 2.0/OIDC/Firebase provider's token authentication methods. The plugin ensures a secure API connection to prevent data compromise and allows access to the WordPress REST APIs from Android/iOS and desktop applications. Successful authentication is required before users can access site resources, making WordPress login endpoints secure from unauthorized access.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in WordPress REST API Authentication 3.6.3

    Fixed

    A plugin for WordPress called WordPress REST API Authentication has a security issue that could allow unauthorized changes to be made to the site. This can lead to a denial of service, meaning that t...

    Read More
  • Input validation vulnerability in WordPress REST API Authentication 2.4.0

    Fixed

    The WordPress REST API Authentication plugin for WordPress has a security issue in versions up to and including 2.4.0. This issue could allow an unauthenticated attacker to make changes to plugin sett...

    Read More