REST API Log
REST API Log has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for REST API Log has a vendor fix available, so running the current release closes it.
All of these findings were reported by Aydan Arabadzha. REST API Log is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-66443REST API Log <= 1.7.1 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records
REST API Log
Author
Pete Nelson
WordPress plugin to log REST API requests and responses (for v2 of the API). Includes: WordPress admin page to view and search log entries API endpoint to access log entries via JSON Filters to customize logging Custom endpoint logging ElasticPress logging Find us on GitHub! Roadmap Better search capabilities for log entries via the REST API endpoint
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C