Executive brief
The miniOrange JWT Authentication plugin for WordPress secures REST API endpoints using JWT tokens, API keys, and other authentication methods configured by administrators. A vulnerability allows unauthenticated attackers to bypass these configured authentication settings by supplying a specific GET parameter, forcing the plugin to fall back to Basic HTTP authentication. Attackers can then enumerate usernames and guess credentials without rate limiting, potentially compromising WordPress sites and their data.
Technical details
The vulnerability is an authentication method downgrade flaw in miniOrange JWT Authentication for WP REST APIs before version 4.8.0. An unauthenticated attacker can supply a specific GET parameter to bypass administrator-configured authentication mechanisms (JWT, API tokens, etc.) without capability checks or nonce verification, forcing the plugin to use Basic HTTP authentication instead. The attacker can then exploit distinguishable error codes and the absence of rate limiting to conduct unthrottled username enumeration and credential guessing attacks against the WordPress REST API. The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function) and requires only network access with no user interaction or authentication required.
Affected products
- miniOrange JWT Authentication for WP REST APIs before 4.8.0
Timeline
- 2026-09-15: disclosed