CRITICAL 9.8 CVE-2026-75860 Published 20 Aug 2026

WordPress JSON Options Plugin Unauthenticated Privilege Escalation

Worried this affects one of your servers?

The JSON Options WordPress plugin, up to version 0.0.4, lacks capability checks and nonce verification on a critical action, making it accessible to unauthenticated users.

Exploiting this vulnerability allows attackers to update arbitrary WordPress options, enabling user registration and setting the default role to administrator, resulting in full site takeover.

Reference: CVE-2026-75860 on NVD

← Back to Security News