What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan.This issue affects Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan: from n/a through 4.34.
Explanation of Vulnerability in Simple Terms
02Summary
The Disable Json API plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of an authenticated site administrator. An attacker can craft a malicious webpage that, when visited by a logged-in admin, triggers unintended changes to plugin settings or site configuration. The vulnerability affects versions up to 4.34 and requires the admin to visit a malicious link or page.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into changing plugin settings or site configuration without their knowledge.
Potential impact on your site
04Site Impact
Plugin settings could be altered by attackers without your consent, potentially disabling security features.
Conditions required to exploit
05Prerequisites
Admin must visit a malicious webpage while logged into WordPress.
Key dates
06Disclosure timeline
December 28, 2023
CVE published
April 28, 2026
Record updated