← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJan 26, 2022 · 18:44via API Security News

Issue 169: Insecure API in WordPress plugin, Tesla 3rd party vulnerability, introducing vAPI

Brief

This week, we have details of a vulnerability in the popular WordPress plugin, WP HTML Mail, which potentially exposed 20,000 WordPress sites, and a vulnerability in TeslaMate software exposing dozens of Teslas to remote access. On more positive news, we have an introduction to vAPI, an open-source laboratory for learning API security, and an article on how to reduce API attack surfaces.

Vulnerability: WordPress sites exposed by insecure REST API

This week, we have another vulnerability in a WordPress plugin , this time the popular WP HTML Mail plugin. The vulnerability is tracked as CVE-2022-0218 with a CVSS score of 8. 3, and it was discovered by Wordfence researcher Chloe Chamberland.

Read more on API Security News