Sceawere

Vulnerability Detail

CVE-2026-97637UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JSON API Auth Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
15h ago
Vendor
parorrey
Product
JSON API Auth
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()` endpoint — which embeds a live WordPress `logged_in` cookie produced by `wp_generate_auth_cookie()` directly in its JSON response body — to serve that cached authenticated response to any subsequent unauthenticated GET request to the same URI. This makes it possible for unauthenticated attackers to retrieve a valid Administrator `logged_in` session cookie from the cached response and use it to fully authenticate as the site Administrator, including via the same plugin's `get_currentuserinfo` endpoint and any cookie-authenticated controller action. Exploitation requires the PI-Media/json-api parent plugin to be installed and active with the Auth controller enabled, and a legitimate Administrator must have POSTed to `/api/auth/generate_auth_cookie/` within the preceding 24-hour cache TTL; the nominal HTTPS enforcement gate present in `Auth.php` is trivially bypassed by supplying `insecure=cool` as a request parameter.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-02T08:17:05.660Z",
  "pubdate": "2026-10-02T08:17:05.660Z",
  "executiveSummary": "The JSON API Auth plugin for WordPress (up to version 3.1.2) contains a critical authentication bypass vulnerability stemming from insecure caching mechanisms in the PI-Media/json-api parent plugin.\nThe vulnerability allows an unauthenticated attacker to obtain a valid, active administrator session cookie via a cached API response.\nThis flaw exists because the parent plugin caches responses based solely on URI and query string parameters, disregarding HTTP methods and POST body content.\nWhen an administrator authenticates via the generate_auth_cookie() endpoint, the resulting response—which includes a sensitive logged_in WordPress session cookie—is stored in a transient.\nAny subsequent GET request to the same endpoint by an unauthenticated user retrieves the cached, authenticated response, granting the attacker the administrator's session token.\nExploitation requires the parent plugin to be active with the Auth controller enabled and a previous administrative authentication event within the 24-hour cache TTL period.\nThe threat is exacerbated by a trivial bypass of the plugin's HTTPS enforcement gate using the insecure=cool parameter.\nSuccessful exploitation results in full administrative account takeover, providing the attacker with complete control over the WordPress instance.",
  "technicalDetails": "The root cause is an improper implementation of response caching within the PI-Media/json-api framework. The framework utilizes WordPress transients to cache controller dispatch outputs but fails to include the HTTP request method or the request body in the unique cache key identifier.\nBecause the system only keys transients by URI and query string, the cache layer becomes unaware of the difference between an unauthenticated GET request and an authenticated POST request targeting the generate_auth_cookie() endpoint.\nThe Auth.php controller function generate_auth_cookie() explicitly returns a JSON object containing a raw WordPress session cookie generated by the wp_generate_auth_cookie() function upon successful administrative login.\nThe vulnerability flow proceeds as follows: First, a legitimate administrator performs a POST request to /api/auth/generate_auth_cookie/, successfully authenticating and generating a valid logged_in session cookie. The PI-Media/json-api parent plugin intercepts this response and caches it in a transient based on the endpoint URI.\nSecond, an unauthenticated attacker identifies the URI path and sends a standard GET request to that exact endpoint. Because the attacker can append the insecure=cool parameter, they bypass the plugin’s nominal HTTPS enforcement check, which is intended to prevent exposure of auth credentials.\nThird, the plugin logic checks the transient cache, finds a match for the requested URI, and serves the cached response. The attacker receives the raw JSON response body containing the administrator's active session cookie.\nWith the stolen cookie, the attacker can impersonate the administrator by injecting the cookie into their browser session or by using it to access authorized endpoints such as get_currentuserinfo, which relies on the standard WordPress cookie-based authentication mechanisms.\nThe impact is total compromise of the WordPress site. The attacker can execute any function accessible to the administrator, including theme/plugin modification, user management, and remote code execution through file uploads or theme editing, effectively bypassing all primary authentication barriers."
}
CVE-2026-97637: JSON API Auth Authentication Bypass (CRITICAL Severity, CVSS: 9.8) | Sceawere