CVE-2019-16332
15.09.2019, 22:15
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
Vendor | Product | Version |
---|---|---|
api_bearer_auth_project | api_bearer_auth | 𝑥 < 2019-09-07 |
𝑥
= Vulnerable software versions
References