REST API Log

REST API Log has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for REST API Log has a vendor fix available, so running the current release closes it.

All of these findings were reported by Aydan Arabadzha. REST API Log is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all REST API Log vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-66443

REST API Log <= 1.7.1 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv1.7.2

REST API Log

Pete Nelson

Author

Pete Nelson

3.6(24)
72/100
Last Updated
2026-07-24 (21d ago)
Active Installs
5,000+
Downloads
122,632
Requires WP
4.7+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2015-07-10 (11y ago)

WordPress plugin to log REST API requests and responses (for v2 of the API). Includes: WordPress admin page to view and search log entries API endpoint to access log entries via JSON Filters to customize logging Custom endpoint logging ElasticPress logging Find us on GitHub! Roadmap Better search capabilities for log entries via the REST API endpoint

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C