🔐 CVE Alert

CVE-2026-81742

HIGH 8.8

BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.

Vendor unknown
Product be rest endpoints
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown be rest endpoints

Be the first to know when new high vulnerabilities affecting unknown be rest endpoints are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / BE REST Endpoints
0 ≤ 1.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/ea7c371a-3d0b-4e09-9c76-145345ad316b/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan