PT-2026-104152 · WordPress · Json Api Auth
CVE-2026-97637
·
Published
2026-10-02
·
Updated
2026-10-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JSON API Auth plugin for WordPress versions prior to 3.1.3
Description
An authentication bypass exists due to cached session cookie disclosure. The PI-Media/json-api parent plugin caches controller dispatch results in transients based only on the URI and query string, ignoring the HTTP method and POST body. Consequently, the
/api/auth/generate auth cookie/ endpoint, which includes a live WordPress logged in cookie generated by wp generate auth cookie(), may serve a cached authenticated response to unauthenticated GET requests. This allows an attacker to obtain a valid Administrator session cookie and authenticate as the site Administrator, potentially accessing the get currentuserinfo endpoint. The issue requires the PI-Media/json-api parent plugin to be active with the Auth controller enabled and a recent Administrator request to the affected endpoint. The HTTPS enforcement in Auth.php can be bypassed by using the insecure parameter.Recommendations
Update the JSON API Auth plugin for WordPress to a version newer than 3.1.2.
As a temporary mitigation, disable the Auth controller within the PI-Media/json-api parent plugin.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Json Api Auth