CVE-2026-89027
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| miniOrange | JWT Authentication for WP REST APIs | 0 < 4.8.0 | affected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
References
- https://wordpress.org/plugins/wp-rest-api-authentication/#developers
- https://www.vulncheck.com/advisories/miniorange-jwt-authentication-for-wp-rest-apis-authentication-downgrade
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.