Junglewise Threat Intelligence

CVE-2026-75860: WordPress JSON Options plugin unauthenticated options update

CVE-2026-75860 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

The JSON Options WordPress plugin, used to manage site configuration settings, contains a critical flaw that allows attackers without any account credentials to modify arbitrary WordPress options through a file upload feature. By exploiting this vulnerability, an attacker can enable user self-registration and set new accounts to administrator role, gaining complete control of the website without authorization.

Technical details

The JSON Options plugin versions through 0.0.4 fail to implement capability checks or CSRF token (nonce) verification on an action that processes file uploads and runs on every HTTP request, making it accessible to unauthenticated users. The vulnerable component accepts a JSON file upload via the `json_options_upload` parameter and applies it to WordPress core options without validation. An attacker can POST a crafted JSON payload containing arbitrary WordPress option names and values (such as `users_can_register` and `default_role`) to update site settings. By setting `users_can_register` to 1 and `default_role` to `administrator`, the attacker can then self-register a new account that automatically receives administrator privileges, leading to full site takeover. No patch is currently available; the plugin requires removal or update to a fixed version.

Affected products

  • JSON Options JSON Options 0.0.4 and earlier

Timeline

  • 2026-08-18: disclosed
  • 2026-08-20: advisory

References