CVE-2019-16332: API Bearer Auth Project API Bearer Auth
Medium severity, CVSS 6.1. EPSS: 5.7% chance of exploitation in the next 30 days.
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
Affected products
- API Bearer Auth Project API Bearer Auth: before 2019-09-07 (fixed in 2019-09-07)
Published 2019-09-15. Last modified 2026-06-17.