WordPress API Bearer Auth plugin before 20190907 contains a cross-site scripting vulnerability. The server parameter is not correctly filtered in swagger-config.yaml.php.
View the template here CVE-2019-16332.yaml
References:
https://wpvulndb.com/vulnerabilities/9868