---
id: CVE-2026-89027
title: >-
  miniOrange JWT Authentication for WP REST APIs plugin for WordPress before
  4.8.0 contains an authentication method downgrade vulnerability that allows
  unauthenticated attackers to bypass administrator-configured authentication by
  supplyi…
summary: >-
  miniOrange JWT Authentication for WP REST APIs plugin for WordPress before
  4.8.0 contains an authentication method downgrade vulnerability that allows
  unauthenticated attackers to bypass administrator-configured authentication by
  supplyi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-306
vendor: miniOrange
product: JWT Authentication for WP REST APIs
affected:
  - jwt_authentication_for_wp_rest_apis < 4.8.0
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89027'
references:
  - url: 'https://wordpress.org/plugins/wp-rest-api-authentication/#developers'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/miniorange-jwt-authentication-for-wp-rest-apis-authentication-downgrade
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00382
epssPercentile: 0.29433
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T16:48:48.988187Z'
ingestedAt: '2026-09-15T20:44:02.608Z'
---

## Overview

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
