Impact
The REST API Log plugin contains an unauthenticated Insecure Direct Object Reference vulnerability that allows any user to retrieve or modify log entries through the plugin’s REST API endpoints. This leads to information disclosure of site operational data and potentially enables tampering with log content. The weakness is a classic IDOR flaw (CWE‑639).
Affected Systems
The vulnerability applies to the WordPress plugin REST API Log developed by Pete Nelson, specifically to all releases up to and including version 1.7.2.
Risk and Exploitability
With a CVSS score of 7.5, the exploit is considered high severity. Although no EPSS score is available, the attack does not require authentication or special preconditions, making exploitation trivial for anyone who can reach the WordPress site. The vulnerability is not listed in CISA’s KEV catalog, but its unauthenticated nature means that impact is likely for any publicly accessible site.
OpenCVE Enrichment