VYPR

JWT Authentication for WP REST APIs

by Miniorange

CVEs (1)

  • CVE-2026-89027MedSep 15, 2026
    risk 0.42cvss 6.5epss

    miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any…