← Back to feed
Vulnerabilities & PatchesEmerging1 sourceDec 23, 2021 · 14:02via API Security News

Issue 165: Vulnerability in All in One WordPress plugin, why to treat all APIs as public, a beginner’s guide to API security

Brief

This week, we have news of another high severity vulnerability in a WordPress plugin, this time the popular All in One allowing compromise via the core REST API. We also have views from @apihandyman on why to treat all APIs as public ones, a comprehensive beginner’s guide to API security, and finally an optimistic view from Forbes on how enterprises can achieve speed and security by adopting Zero Trust and APIs.

This is the final APISecurity. io newsletter for 2021. We wish all subscribers happy holidays and a prosperous New Year, and look forward to welcoming you back with issue 166 on the 6th January 2022!

Vulnerability: high severity vulnerability in the All in One WordPress plugin

Vulnerabilities in WordPress plugins have featured frequently in this newsletter ( here and here ) and again this week we feature a pair of high severity vulnerabilities in the popular All in One plugin.

Read more on API Security News