{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/json-api-auth--3.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:json_api_auth:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-97637"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JSON API Auth (\u003c= 3.1.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","web-application","authentication-bypass","cve"],"_cs_type":"threat","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eCVE-2026-97637 describes an authentication bypass vulnerability affecting versions of the JSON API Auth plugin for WordPress up to and including 3.1.2. The vulnerability originates in the PI-Media/json-api parent plugin, which improperly caches controller dispatch results based solely on URI and query strings. Crucially, this caching mechanism fails to distinguish between HTTP methods or evaluate the contents of POST bodies.\u003c/p\u003e\n\u003cp\u003eThe plugin's \u003ccode\u003egenerate_auth_cookie()\u003c/code\u003e endpoint, which returns a valid WordPress \u003ccode\u003elogged_in\u003c/code\u003e session cookie within the JSON response body, becomes susceptible to this caching flaw. When an administrator performs an authentication action via POST, the result is cached. An unauthenticated attacker can subsequently issue a GET request to the same URI to retrieve the cached response, including the valid administrator cookie. By also supplying the \u003ccode\u003einsecure=cool\u003c/code\u003e parameter, an attacker can bypass the plugin's HTTPS enforcement check. Successful exploitation leads to full administrative account takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker monitors traffic or waits for a target site administrator to perform a legitimate POST request to \u003ccode\u003e/api/auth/generate_auth_cookie/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe vulnerable PI-Media/json-api plugin processes the administrator's request and stores the controller result, including the sensitive \u003ccode\u003elogged_in\u003c/code\u003e session cookie, in the server cache.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the specific URI and query parameters associated with the administrator's recent authentication event.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious GET request targeting the same URI, appending the \u003ccode\u003einsecure=cool\u003c/code\u003e parameter to bypass HTTPS validation logic.\u003c/li\u003e\n\u003cli\u003eThe server identifies a cache hit for the URI and returns the stored JSON response, effectively leaking the administrator's session cookie to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the \u003ccode\u003elogged_in\u003c/code\u003e session cookie from the received JSON response.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen session cookie to authenticate to the WordPress site as an administrator.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative access to the site, allowing for configuration changes, malicious plugin installation, or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative account takeover of the affected WordPress site. Given the plugin's role, this provides attackers with persistent access, the ability to execute arbitrary administrative tasks, install malicious code, or exfiltrate sensitive site data. Organizations using the JSON API Auth plugin are at risk of complete site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the JSON API Auth plugin to a version addressing CVE-2026-97637. If an update is unavailable, disable the JSON API Auth plugin immediately.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit web server access logs for requests targeting \u003ccode\u003e/api/auth/generate_auth_cookie/\u003c/code\u003e that include the \u003ccode\u003einsecure=cool\u003c/code\u003e parameter, as this is a high-confidence indicator of exploitation attempts.\u003c/li\u003e\n\u003cli\u003eAudit administrative user session activity for unauthorized logins following observed GET requests to the identified API endpoints.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block any incoming HTTP requests containing the \u003ccode\u003einsecure=cool\u003c/code\u003e parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:22:54Z","date_published":"2026-10-02T08:22:54Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wordpress-json-api-auth-bypass/","summary":"An authentication bypass vulnerability in the WordPress JSON API Auth plugin allows unauthenticated attackers to hijack administrative sessions via cached HTTP responses.","title":"Authentication Bypass in WordPress JSON API Auth Plugin (CVE-2026-97637)","url":"https://feed.craftedsignal.io/briefs/2026-10-wordpress-json-api-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - JSON API Auth (\u003c= 3.1.2)","version":"https://jsonfeed.org/version/1.1"}