CRITICAL
JSON Options
CVE published 2026-08-20
CVE-2026-75860
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T06:17:32.207Z and has not been modified since then. The NVD entry is currently Deferred. The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing [truncated]