Impact
The BE REST Endpoints WordPress plugin up to version 1.0.0 allows widgets to be read, created, updated, or deleted without performing any authorization checks. the data it stores, creating an input validation weakness (CWE‑79). This flaw permits an unauthenticated attacker to inject arbitrary JavaScript into a widget value, which will be rendered and executed in the browser of any user who loads the site or the widget content. The injected script runs with the privileges of the visitor, potentially exposing session data or allowing other client‑side attacks.
Affected Systems
WordPress sites that have installed the BE REST Endpoints plugin in a version equal to or older than 1.0.0 are affected. The vulnerability is independent of the site's user roles since the plugin’s REST endpoints are accessible to all visitors.
Risk and Exploitability
The CVSS score of 8.8 denotes a high‑severity flaw, while the EPSS score of less than 1 % indicates a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The absence of authentication and sanitization checks allows an attacker to perform REST API requests without credentials, leading to injection of malicious JavaScript any site visitor, compromising client‑side confidentiality and integrity.
OpenCVE Enrichment