Description
WordPress Plugin WP REST API (WP API) is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to serve up arbitrary Flash SWF files from the API, allowing these Flash files to bypass browser cross-origin domain policies. WordPress Plugin WP REST API (WP API) version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin Advanced Booking Calendar SQL Injection (1.6.1)
WordPress Plugin W3 Total Cache Information Disclosure (0.9.2.4)
Family Connections Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0699)
e107 Other Vulnerability (CVE-2010-0996)
SharePoint Improper Input Validation Vulnerability (CVE-2019-1257)