CVE-2026-75860
Last modified
CVE-2026-75860 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | JSON Options | <= 0.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75860?
How severe is CVE-2026-75860?
How do I fix CVE-2026-75860?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75855ArcadeDB versions before 26.8.1 fail to sanitize database na…8.7
- CVE-2026-75856CodeWhale before 0.8.64 contains a server-side request forge…8.6
- CVE-2026-75857CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerab…7
- CVE-2026-75858CodeWhale (packages codewhale / codewhale-tui) versions >= 0…7.8
- CVE-2026-75859CodeWhale versions before 0.8.64 fail to validate file paths…7.5
- CVE-2026-7586A weakness has been identified in Open5GS up to 2.7.7. Affec…4.3
- CVE-2026-75861The Ultimate Gift Cards for WooCommerce WordPress plugin bef…6.5
- CVE-2026-75862Photoshop Desktop is affected by an Integer Overflow or Wrap…7.8
- CVE-2026-75863Photoshop Desktop is affected by an Integer Overflow or Wrap…7.8
- CVE-2026-75865The WPLP Cookie Consent – Cookie Banner & Consent Management…9.8
- CVE-2026-75866Punk::OAuth2::Server versions through 0.03 for Perl issue ac…9.1
- CVE-2026-7587A vulnerability has been found in Open5GS up to 2.7.7. This …4.3
Are you affected by CVE-2026-75860?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
