CVE-2024-6624

CRITICAL

JSON API User <3.9.3 - Privilege Escalation

Title source: llm

Description

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

Exploits (2)

nomisec WORKING POC 3 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-6624
nomisec WORKING POC 1 stars
by Jenderal92 · poc
https://github.com/Jenderal92/CVE-2024-6624

Scores

CVSS v3 9.8
EPSS 0.3928
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

Status published

Affected Products (1)

parorrey/json_api_user < 3.9.4

Timeline

Published Jul 11, 2024
Tracked Since Feb 18, 2026