Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89027— miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade

Quick assessment

Affected
miniOrange JWT Authentication for WP REST APIs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 “miniOrange JWT Authentication for WP REST APIs” 插件在 4.8.0 版本之前存在一个“认证方式降级”漏洞。该漏洞允许未认证的 attackers(攻击者)通过提供一个特定的 GET 请求参数,绕过管理员配置的认证机制,且该参数不需要任何权限(capability)检查或 nonce 验证。 攻击者可以强制插件使用 Basic HTTP 认证方式,无视已配置的 JWT 或 API token 设置。随后,攻击者可利用可区分的错误代码以及缺乏频率

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89027

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade
Source: CVE Program / CVE List V5
Vulnerability Description
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
miniOrange JWT Authentication for WP REST APIs 0 ~ 4.8.0 -

II. Public POCs for CVE-2026-89027

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89027

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89027 (1)

Vendor Pages for CVE-2026-89027 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89027

No comments yet


Leave a comment