CVE-2026-89027
Deferred Deferred - Pending Action

Authentication Bypass in miniOrange JWT Auth WordPress Plugin

Vulnerability report for CVE-2026-89027, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-24

Assigner: VulnCheck

Description

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-24
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
miniorange jwt_authentication_for_wp_rest_apis to 4.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication method downgrade flaw in the miniOrange JWT Authentication for WP REST APIs plugin for WordPress before version 4.8.0. It allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without capability checks or nonce verification. Attackers can force the plugin to use Basic HTTP authentication instead of configured JWT or API token settings.

Detection Guidance

Check if the plugin version is below 4.8.0 by inspecting the WordPress admin panel under Plugins. Look for error responses from REST API endpoints that reveal user enumeration or authentication failures. Monitor network traffic for Basic HTTP authentication attempts when JWT or API tokens are expected.

Impact Analysis

Attackers can exploit this vulnerability to perform unthrottled username enumeration and credential guessing attacks. The flaw enables distinguishable error codes and the absence of rate limiting, making it easier for attackers to guess valid credentials and gain unauthorized access to the WordPress site.

Compliance Impact

This vulnerability allows unauthenticated attackers to bypass authentication, enabling unauthorized access to WordPress REST APIs. This could lead to exposure of sensitive user data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information if such data is processed by the plugin.

Mitigation Strategies

Update the plugin to version 4.8.0 or later immediately. Disable Basic HTTP authentication if not required. Implement rate limiting on REST API endpoints. Review and restrict user roles with API access. Monitor logs for suspicious authentication attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89027. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart