PT-2026-78895 · WordPress · Json Options

·

CVE-2026-75860

·

Published

2026-08-20

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JSON Options versions prior to 0.0.5
Description The JSON Options WordPress plugin lacks capability checks and nonce verification on an action that executes on every request. This allows unauthenticated users to update arbitrary WordPress options. An attacker can exploit this to enable user registration and set the default role to administrator, resulting in privilege escalation and full site takeover.
Recommendations Update JSON Options to a version newer than 0.0.4.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75860

Affected Products

Json Options