Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3j9-5wcv-qwj3

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

EPSS

Процентиль: 30%
0.00365
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.5
nvd
3 дня назад

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

CVSS3: 6.5
debian
3 дня назад

miniOrange JWT Authentication for WP REST APIs plugin for WordPress be ...

EPSS

Процентиль: 30%
0.00365
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306