Description
WordPress Plugin JSON API User is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin JSON API User version 3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin Google Maps by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0249)
GeoServer Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-51444)
Apache HTTP Server CVE-2003-0789 Vulnerability (CVE-2003-0789)