PT-2026-104152 · WordPress · Json Api Auth

CVE-2026-97637

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JSON API Auth plugin for WordPress versions prior to 3.1.3
Description An authentication bypass exists due to cached session cookie disclosure. The PI-Media/json-api parent plugin caches controller dispatch results in transients based only on the URI and query string, ignoring the HTTP method and POST body. Consequently, the /api/auth/generate auth cookie/ endpoint, which includes a live WordPress logged in cookie generated by wp generate auth cookie(), may serve a cached authenticated response to unauthenticated GET requests. This allows an attacker to obtain a valid Administrator session cookie and authenticate as the site Administrator, potentially accessing the get currentuserinfo endpoint. The issue requires the PI-Media/json-api parent plugin to be active with the Auth controller enabled and a recent Administrator request to the affected endpoint. The HTTPS enforcement in Auth.php can be bypassed by using the insecure parameter.
Recommendations Update the JSON API Auth plugin for WordPress to a version newer than 3.1.2. As a temporary mitigation, disable the Auth controller within the PI-Media/json-api parent plugin.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97637

Affected Products

Json Api Auth