Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-16061: WordPress Rest Routes plugin lets strangers run database commands

CVE-2026-16061 · published 5 days ago
Summary

The Rest Routes plugin for WordPress (up to version 5.5.5) accepts data from a web address without checking it, then uses that data in a database query. This means anyone on the internet could trick the site into running unwanted commands on the database, potentially exposing or altering data. Update the plugin to the latest version or replace it with a secure alternative as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown rest routes <= 5.5.5
Original advisory text
Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
Severity
8.6 High
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-16061 · MITRE
Monitor software like this
Free during beta