CVE-2026-89027
miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.
| CWE | CWE-306 |
| Vendor | miniorange |
| Product | jwt authentication for wp rest apis |
| Published | Sep 15, 2026 |
Get instant alerts for miniorange jwt authentication for wp rest apis
Be the first to know when new medium vulnerabilities affecting miniorange jwt authentication for wp rest apis are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N