WordPress API Bearer Auth plugin before 20190907 contains a cross-site scripting vulnerability. The server parameter is not correctly filtered in swagger-config.yaml.php.
id: CVE-2019-16332
info:
name: WordPress API Bearer Auth <20190907 - Cross-Site Scripting
autho
...