Description
WordPress Plugin JSON API User is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin JSON API User version 3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin aoringo CAT setter Cross-Site Scripting (0.1.1)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-44040)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1210)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)
ownCloud Improper Authentication Vulnerability (CVE-2014-9045)