CVE-2026-89027: miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade

Published Sep 15, 2026
·
Updated

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

Affected Software

1 affected component
miniOrange JWT Authentication for WP REST APIs<4.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade miniOrange JWT Authentication for WP REST APIs to a version that resolves this vulnerability.

    Fixed in 4.8.0
  2. Compensating control

    Mitigate username enumeration/credential guessing by adding or enabling rate limiting for requests to the affected WordPress REST API endpoints protected/handled by the miniOrange JWT Authentication for WP REST APIs plugin, since the issue describes the absence of rate limiting.

Event History

Sep 15, 2026
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

WordPress sites using the miniOrange JWT Authentication for WP REST APIs plugin before version 4.8.0 are exposed. The issue is reachable remotely and does not require an authenticated WordPress account.

2

What does an attacker need to exploit it?

An attacker only needs to send requests containing the specific GET parameter that forces the plugin to use Basic HTTP authentication. No capability check or nonce verification is required for that downgrade.

3

What can an attacker do after forcing the authentication downgrade?

The attacker can use distinguishable error codes to enumerate usernames and conduct credential-guessing attacks without rate limiting. Successful credential guessing could provide access using valid account credentials.

4

How can I tell whether my site is affected?

Check whether the miniOrange JWT Authentication for WP REST APIs plugin is installed and whether its version is earlier than 4.8.0. Sites configured for JWT or API token authentication should also verify whether requests can force Basic HTTP authentication through the affected GET parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203