CVE-2019-16332

MEDIUM NUCLEI

api_bearer_auth < 2019-09-07 - Cross-Site Scripting via Server Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-16332 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.

Nuclei Templates (1)

WordPress API Bearer Auth <20190907 - Cross-Site Scripting
MEDIUMby daffainfo

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9868
Third Party Advisory x_refsource_misc
https://plugins.trac.wordpress.org/changeset/2152730

Scores

CVSS v3 6.1
EPSS 0.0570
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
api_bearer_auth_project/api_bearer_auth < 2019-09-07
Published Sep 15, 2019
Tracked Since Feb 18, 2026