The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated… (CVE-2026-81742)
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
AI Analysis
Technical Summary
CVE-2026-81742 describes a vulnerability in the BE REST Endpoints WordPress plugin through version 1.0.0 where no authorization checks are performed on widget management REST endpoints. This allows unauthenticated attackers to manipulate widgets arbitrarily. Furthermore, the plugin fails to sanitize widget values, leading to stored cross-site scripting (XSS) attacks that execute malicious scripts in the browsers of users visiting the affected site.
Potential Impact
An attacker can perform unauthorized widget operations including reading, creating, updating, and deleting widgets. The lack of input sanitization allows injection of malicious scripts, resulting in stored XSS that can compromise the confidentiality, integrity, and availability of the site and its users. The CVSS score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the REST API endpoints if possible or disable the plugin to prevent exploitation.
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated… (CVE-2026-81742)
Description
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
CVSS v3.1
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-81742 describes a vulnerability in the BE REST Endpoints WordPress plugin through version 1.0.0 where no authorization checks are performed on widget management REST endpoints. This allows unauthenticated attackers to manipulate widgets arbitrarily. Furthermore, the plugin fails to sanitize widget values, leading to stored cross-site scripting (XSS) attacks that execute malicious scripts in the browsers of users visiting the affected site.
Potential Impact
An attacker can perform unauthorized widget operations including reading, creating, updating, and deleting widgets. The lack of input sanitization allows injection of malicious scripts, resulting in stored XSS that can compromise the confidentiality, integrity, and availability of the site and its users. The CVSS score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the REST API endpoints if possible or disable the plugin to prevent exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qmr6-ghgr-83xm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81742"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa5eff955bf5e2cf5ef6f99
Added to database: 09/13/2026, 00:36:09 UTC
Last enriched: 09/13/2026, 00:37:49 UTC
Last updated: 09/13/2026, 04:01:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.