CVE-2026-16061
Received Received - Intake

SQL Injection in Rest Routes WordPress Plugin

Vulnerability report for CVE-2026-16061, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_plugin rest_routes to 5.5.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Rest Routes WordPress plugin through version 5.5.5 has a vulnerability where it does not properly sanitize and validate a value taken from a public REST route URL before using it in a SQL query. This allows unauthenticated attackers to perform SQL injection attacks.

Detection Guidance

To detect this vulnerability, inspect your WordPress site for the Rest Routes plugin version 5.5.5 or below. Check for unusual SQL query patterns or errors in server logs. Use tools like WPScan to scan for vulnerable endpoints.

Impact Analysis

This vulnerability allows attackers to execute malicious SQL commands on your WordPress database without needing authentication. This could lead to unauthorized data access, modification, or deletion, potentially compromising sensitive information stored in your site.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of personal data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations could face legal penalties, fines, or reputational damage if such an incident occurs.

Mitigation Strategies

Immediately update the Rest Routes plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Monitor network traffic for suspicious SQL injection attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16061. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart