Description
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to plugin log data
Action: Immediate Patch
AI Analysis

Impact

The REST API Log plugin contains an unauthenticated Insecure Direct Object Reference vulnerability that allows any user to retrieve or modify log entries through the plugin’s REST API endpoints. This leads to information disclosure of site operational data and potentially enables tampering with log content. The weakness is a classic IDOR flaw (CWE‑639).

Affected Systems

The vulnerability applies to the WordPress plugin REST API Log developed by Pete Nelson, specifically to all releases up to and including version 1.7.2.

Risk and Exploitability

With a CVSS score of 7.5, the exploit is considered high severity. Although no EPSS score is available, the attack does not require authentication or special preconditions, making exploitation trivial for anyone who can reach the WordPress site. The vulnerability is not listed in CISA’s KEV catalog, but its unauthenticated nature means that impact is likely for any publicly accessible site.

Generated by OpenCVE AI on October 1, 2026 at 15:53 UTC.

Remediation

Vendor Solution

Update the WordPress REST API Log plugin to the latest available version (at least 1.7.3).


OpenCVE Recommended Actions

  • Update the REST API Log plugin to version 1.7.3 or later
  • If an immediate update is not feasible, remove or disable the plugin to eliminate the exposed API paths
  • Restrict access to the REST API endpoints by configuring the web server or a security plugin to allow only authenticated requests

Generated by OpenCVE AI on October 1, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Title WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:59:33.462Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:17.660

Modified: 2026-10-01T16:17:27.987

Link: CVE-2026-100514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:00:11Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key