Privilege Escalation Vulnerability in REST API Custom API Generator for WordPress
CVE-2025-5288
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 June 2025
What is CVE-2025-5288?
The REST API | Custom API Generator for WordPress is exposed due to a missing capability check in the process_handler() function. This vulnerability allows unauthenticated users to exploit the system by sending a POST request with a crafted import_api URL. As a result, attackers can import malicious JSON data that enables them to create new users with full Administrator privileges, thereby compromising the integrity and security of the affected WordPress installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 <= 2.0.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved