PT-2026-78895 · WordPress · Json Options
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JSON Options versions prior to 0.0.5
Description
The JSON Options WordPress plugin lacks capability checks and nonce verification on an action that executes on every request. This allows unauthenticated users to update arbitrary WordPress options. An attacker can exploit this to enable user registration and set the default role to administrator, resulting in privilege escalation and full site takeover.
Recommendations
Update JSON Options to a version newer than 0.0.4.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Json Options