WordPress Plugin WP REST API (WP API) is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP REST API (WP API) version 1.2 is vulnerable; prior versions may also be affected.
Update to plugin version 1.2.1 or latest
WordPress 4.8.x Cross-Domain Flash Injection Vulnerability (4.8 - 4.8.4)
WordPress Plugin Quick Paypal Payments Cross-Site Scripting (3.0)
WordPress Plugin WordPress Download Manager Remote Code Execution (2.7.4)
WordPress Plugin WP Learn Manager Security Bypass (1.1.4)