Description
WordPress Plugin JSON API User is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin JSON API User version 3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.4 or latest
References
Related Vulnerabilities
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41892)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000356)
WordPress Plugin WP Mobile Menu-The Mobile-Friendly Responsive Menu Security Bypass (2.7.2)
CakePHP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35239)
WordPress Plugin BuddyPress Activity Plus Multiple Vulnerabilities (1.6.1)