Access violation vulnerability in REST API | Custom API Generator For Cross Platform And Import Export In WP 2.0.3

The REST API plugin for WordPress, called “Custom API Generator For Cross Platform And Import Export In WP,” has a security vulnerability that allows unauthorized users to gain more privileges than they should have. This is because the plugin does not have a proper check in place to confirm a user’s capabilities. This means that someone without an account or proper authorization can send a specific URL and information to the plugin, creating a new user with full administrative access.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.