Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin WP REST API (WP API) Cross-Site Request Forgery (1.1) - Vulnerability Database

WordPress Plugin WP REST API (WP API) Cross-Site Request Forgery (1.1)

Description

WordPress Plugin WP REST API (WP API) is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to serve up arbitrary Flash SWF files from the API, allowing these Flash files to bypass browser cross-origin domain policies. WordPress Plugin WP REST API (WP API) version 1.1 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 1.1.1 or latest