CVE-2026-100514: WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Affected Software
1 affected component
WordPress REST API Log plugin<=1.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress REST API Log pluginto a version that resolves this vulnerability.Fixed in 1.7.3
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The network attack vector indicates it can be targeted remotely.
2
What is the potential impact?
The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact identified. Exploitation could expose information accessible through the affected object references.
3
Which plugin versions are affected?
REST API Log versions 1.7.2 and earlier are identified as affected.