WP Cerber < 8.9.3 contains a bypass of /wp-json access control caused by improper handling of trailing '?' character, letting unauthorized users access protected REST API endpoints, exploit requires sending a request with a trailing '?'.
id: CVE-2021-37598
info:
name: WP Cerber < 8.9.3 - Broken Access Control
author: theamanrawat
...