Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks. | |
| Title | miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T16:49:01.480Z
Reserved: 2026-09-10T16:23:54.472Z
Link: CVE-2026-89027
Updated: 2026-09-17T16:48:57.439Z
Status : Received
Published: 2026-09-15T20:19:20.093
Modified: 2026-09-17T17:16:52.763
Link: CVE-2026-89027
No data.
OpenCVE Enrichment
Updated: 2026-09-17T00:45:08Z