Issue with register_rest_route and missing permission_callback
-
Dear WP Table Builder Support Team,
I hope this email finds you well.
I am writing to report a potential security issue I encountered while using the WP Table Builder plugin on my WordPress website. Specifically, I am seeing several errors related to the
register_rest_route
function in my Query Monitor logs.The errors indicate that the REST API route definitions for the following endpoints are missing the required
permission_callback
argument:- wp-table-builder/v1/table
- wp-table-builder/v1/tables
- wp-table-builder/v1/patterns
- wp-table-builder/v1/trash
- wp-table-builder/v1/delete
- wp-table-builder/v1/restore
- wp-table-builder/v1/duplicate
- wp-table-builder/v1/trash_bulk
- wp-table-builder/v1/restore_bulk
According to the WordPress documentation, the
permission_callback
argument is essential for controlling access to REST API routes and ensuring security. Without it, these routes may be publicly accessible, which could pose a security risk.I am using the latest version of WP Table Builder, but the issue persists.
I would greatly appreciate it if you could investigate this issue and release an update to address it as soon as possible.
Thank you for your time and attention to this matter.
Sincerely,
Francisco
https://www.latinajadelgourmet.com
The page I need help with: [log in to see the link]
- You must be logged in to reply to this topic.