← Back to browse · API

CVE-2024-6624

Severity
CRITICAL
CVSS
9.8
EPSS
0.0287
Risk score
40.2
CISA KEV
No
PoC
Yes
Published
2024-07-11
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-47683, GHSA-MXF2-3XCV-2MF9
Products
parorrey:JSON API User 0 ≤3.9.3
Sources
packetstorm 27561a36bc00ccf9cdd8179f|CVE-2024-6624
euvd EUVD-2024-47683

Description

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

References