Impact
The JSON Options WordPress plugin up to version 0.0.4 performs an option‑update action on every request without verifying that the caller has any capability or providing a nonce, so an unauthenticated user can modify any WordPress option. By toggling the registration setting and setting the default role to administrator, the attacker can create new admin accounts and gain full control of the site.
Affected Systems
WordPress sites that have the JSON Options plugin installed and enabled in any version older than 0.0.4 are affected. The plugin is listed under the vendor “Unknown:JSON Options.” No further version details are specified beyond the 0.0.4 ceiling.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, and the EPSS score of less than 1% indicates it is unlikely to be widely exploited yet. Because the flaw is open to every unauthenticated visitor, an attacker can launch the exploit from any web browser or automated script without needing credentials. The vulnerability is not currently catalogued as a known exploited vulnerability by CISA.
OpenCVE Enrichment