CVE-2026-81742
BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
| Vendor | unknown |
| Product | be rest endpoints |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown be rest endpoints
Be the first to know when new high vulnerabilities affecting unknown be rest endpoints are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / BE REST Endpoints
0 ≤ 1.0.0
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan