Executive brief
The Rest Routes WordPress plugin provides REST API endpoints to manage database tables. Through version 5.5.5, a public REST endpoint fails to properly validate user input in the table name parameter, allowing unauthenticated attackers to inject arbitrary SQL code and access, modify, or delete database contents without any credentials.
Technical details
The vulnerability is a SQL injection (SQLi) flaw in the custom-tables/tables/{table_name} REST route. The plugin takes the table_name parameter directly from the REST API URL and uses it in SQL queries without sanitization or validation. The attack is unauthenticated and network-accessible; no prior authentication or special privileges are required. An attacker can craft a malicious table_name value containing SQL syntax to execute arbitrary database queries, potentially leading to data exfiltration, data modification, or denial of service. No patch information is currently available.
Affected products
- Ionut Bizau The Rest Routes through 5.5.5
Timeline
- 2026-08-27: disclosed
- 2026-08-29: advisory: NVD published
- 2026-09-23: other: Last updated