The WordPress REST API in versions 4.7.x before 4.7.2 had a vulnerability where an attacker could modify arbitrary pages without needing an integer identifier. This was done by making a request to the URL wp-json/wp/v2/posts followed by a numeric value and a non-numeric value