๐Ÿ” CVE Alert

CVE-2026-89027

MEDIUM 6.5

miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

CWE CWE-306
Vendor miniorange
Product jwt authentication for wp rest apis
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for miniorange jwt authentication for wp rest apis

Be the first to know when new medium vulnerabilities affecting miniorange jwt authentication for wp rest apis are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

miniOrange / JWT Authentication for WP REST APIs
0 < 4.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/wp-rest-api-authentication/#developers vulncheck.com: https://www.vulncheck.com/advisories/miniorange-jwt-authentication-for-wp-rest-apis-authentication-downgrade

Credits

Choriyev Qahramon (ciprobe) VulnCheck