Input validation vulnerability in WP REST API (WP API) 1.1

The JSON REST API plugin for WordPress may be at risk of Cross-Site Request Forgery in versions 1.1 and earlier. This is because of an issue with the validation of nonces, which are used to prevent forged requests. This means that attackers who can convince a website administrator to click on a link might be able to carry out a “JSON Flash” attack, which is a type of attack that uses a forged request.

Detected in:

WP REST API (WP API) open vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.