CVE-2024-6624

CRITICAL

JSON API User <3.9.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-6624. PoCs published by RandomRobbieBF, Jenderal92.

AI-analyzed exploit summary This PoC exploits an unauthenticated privilege escalation vulnerability in the WordPress JSON API User plugin (versions <= 3.9.3) by registering a new user and then updating their metadata to grant administrator privileges. The exploit leverages improper controls on custom user meta fields.

Description

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

Exploits (2)

nomisec WORKING POC 3 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-6624

This PoC exploits an unauthenticated privilege escalation vulnerability in the WordPress JSON API User plugin (versions <= 3.9.3) by registering a new user and then updating their metadata to grant administrator privileges. The exploit leverages improper controls on custom user meta fields.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress JSON API User plugin <= 3.9.3
No auth needed
Prerequisites: WordPress site with JSON API User plugin installed and active · JSON API plugin must also be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Jenderal92 · poc
https://github.com/Jenderal92/CVE-2024-6624

This Python script exploits CVE-2024-6624, an unauthenticated privilege escalation vulnerability in the JSON API User WordPress plugin (versions <= 3.9.3). It automates user registration and privilege escalation to administrator by leveraging insecure nonce generation and user meta updates.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: JSON API User WordPress plugin <= 3.9.3
No auth needed
Prerequisites: Target running vulnerable JSON API User plugin · Network access to WordPress API endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0287
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
parorrey/JSON API User < 3.9.3
parorrey/json_api_user < 3.9.4
Published Jul 11, 2024
Tracked Since Feb 18, 2026