VYPR

JSON API User

by WordPress

CVEs (2)

  • CVE-2024-6624CriJul 11, 2024
    risk 0.57cvss 9.8epss 0.03

    The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site.…

  • CVE-2026-9626Jul 3, 2026
    risk 0.00cvss epss 0.00

    The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes…