CVE-2025-5288
REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated Privilege Escalation via process_handler Function
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api URL, import specially crafted JSON, and thereby create a new user with full Administrator privileges.
| CWE | CWE-862 |
| Vendor | weboccults |
| Product | rest api | custom api generator for cross platform and import export in wp |
| Published | Jun 13, 2025 |
| Last Updated | Jun 13, 2025 |
Stay Ahead of the Next One
Get instant alerts for weboccults rest api | custom api generator for cross platform and import export in wp
Be the first to know when new critical vulnerabilities affecting weboccults rest api | custom api generator for cross platform and import export in wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
weboccults / REST API | Custom API Generator For Cross Platform And Import Export In WP
1.0.0 โค 2.0.3
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/0e2774fc-f028-436c-a8af-3c17378b9743?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/import-export-with-custom-rest-api/tags/2.0.3/backend/methods/wot-rapi-import-functions.php#L123 wordpress.org: https://wordpress.org/plugins/import-export-with-custom-rest-api/#developers
Credits
Kenneth Dunn