Critical Vulnerability in JSON Options WordPress Plugin Allows Full Site Takeover
A critical vulnerability, CVE-2026-75860, with a CVSS score of 9.8, was discovered in the JSON Options WordPress plugin (version 0.0.4 and below). This vulnerability allows unauthenticated users to update arbitrary WordPress options, potentially leading to privilege escalation and full site takeover. The plugin's lack of capability checks and nonce verification on one of its actions enables this exploit. Immediate patching or removal of the plugin is recommended.