Summary
CVE-2026-16061 is an unauthenticated SQL injection vulnerability in the Rest Routes WordPress plugin, affecting all versions up to and including 5.5.5. The plugin fails to sanitize and validate a value taken from the URL of a public REST API endpoint before using it in a database query, allowing unauthenticated remote attackers to inject and execute arbitrary SQL. The flaw carries a CVSS v3.1 base score of 8.6 (High).
Technical details
- Root cause: The plugin does not sanitize or validate a URL-supplied parameter before incorporating it into a SQL query (CWE-89, SQL Injection).
- Vulnerable endpoint: The
custom-tables/tables/{table_name}REST route, exposed publicly by the plugin. - Trigger conditions: An attacker sends a crafted HTTP request to the vulnerable REST route with a malicious value in the
{table_name}(or related) parameter; no authentication or user interaction is required. - Attack vector: Network — exploitable remotely over HTTP against any WordPress site with the vulnerable plugin active.
- Impact: Successful exploitation allows extraction of data from the WordPress database (per the CVSS vector, impact is scoped to confidentiality) and could expose sensitive information such as user credentials, tokens, or other stored data, depending on database contents and configuration.
Affected software
- Rest Routes WordPress plugin — all versions from the earliest release through 5.5.5 (inclusive).
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - Network attack vector, low attack complexity, no privileges or user interaction required, scope changed, high confidentiality impact.
Mitigation and recommended actions
- Immediate: As of the time of writing, no patched version of Rest Routes has been released. Security teams should treat this as an unmitigated risk.
- Recommended actions in the absence of a patch:
- Deactivate and remove the Rest Routes plugin from affected WordPress sites until a fixed version is available.
- Restrict or block external access to the
custom-tables/tables/{table_name}REST route (e.g., via a web application firewall or reverse proxy rule) if the plugin cannot be immediately removed. - Monitor web server and WordPress logs for anomalous requests to REST API routes containing SQL metacharacters or injection payloads.
- Continue to check the plugin’s changelog/repository for an official security update and apply it as soon as it becomes available.

