VYPR

JSON API User

by WordPress

CVEs (1)

  • CVE-2024-6624CriJul 11, 2024
    risk 0.60cvss 9.8epss 0.43

    The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site.…