CVE-2026-16547
Received Received - Intake

Unauthenticated Log Download in REST API Log WordPress Plugin

Vulnerability report for CVE-2026-16547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any entry, which may contain sensitive data such as credentials, authentication tokens or private content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpsecure rest_api_log to 1.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The REST API Log WordPress plugin before version 1.7.1 has a vulnerability where the token used to protect log downloads is not tied to a specific log entry. This means an attacker with any valid token can download logs from any entry, even without proper authentication. These logs may contain sensitive data like credentials or private content.

Detection Guidance

Check if the REST API Log WordPress plugin version is below 1.7.1. Inspect network traffic for unauthorized log download requests or tokens being exposed. Review logs for sensitive data leaks such as credentials or authentication tokens.

Impact Analysis

This vulnerability allows unauthorized users to access sensitive data such as credentials, authentication tokens, or private content stored in REST API logs. If exploited, it could lead to data breaches, account takeovers, or unauthorized access to confidential information.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR, HIPAA, or other regulations by exposing personal or sensitive data. Organizations may face legal penalties, fines, or reputational damage due to unauthorized data exposure.

Mitigation Strategies

Update the REST API Log plugin to version 1.7.1 or later. Remove any exposed tokens and invalidate them. Audit logs for potential sensitive data leaks and restrict access to logs containing sensitive information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart