1 results (0.001 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 2

12 Jun 2025 — The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api URL, import specially crafted JSON, and thereby create a new user with full Administrator privileges. WordPress REST API | Custom API Generator For Cross Platform And Import Export In WP plugin... • https://packetstorm.news/files/id/200844 • CWE-862: Missing Authorization •