cve/2025/CVE-2025-5288.md

20 lines
1.1 KiB
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2025-5288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5288)
![](https://img.shields.io/static/v1?label=Product&message=REST%20API%20%7C%20Custom%20API%20Generator%20For%20Cross%20Platform%20And%20Import%20Export%20In%20WP&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%20Missing%20Authorization&color=brightgreen)
### Description
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api URL, import specially crafted JSON, and thereby create a new user with full Administrator privileges.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Nxploited/CVE-2025-5288
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/nomi-sec/PoC-in-GitHub