critical · CVSS v3 9.8 · EPSS 0.00636
CVE-2026-97637
The WordPress JSON API Auth plugin (up to 3.1.2) caches responses without considering HTTP method or POST body, allowing unauthenticated use
Overview
The WordPress JSON API Auth plugin (up to 3.1.2) caches responses without considering HTTP method or POST body, allowing unauthenticated users to retrieve a live admin session cookie from the generate_auth_cookie endpoint. This exposes a valid Administrator logged_in cookie that can be used to impersonate the site admin. The flaw requires the PI-Media/json-api parent plugin to be active and an admin to have posted to the endpoint within the 24‑hour cache TTL.
Description
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()` endpoint — which embeds a live WordPress `logged_in` cookie produced by `wp_generate_auth_cookie()` directly in its JSON response body — to serve that cached authenticated response to any subsequent unauthenticated GET request to the same URI. This makes it possible for unauthenticated attackers to retrieve a valid Administrator `logged_in` session cookie from the cached response and use it to fully authenticate as the site Administrator, including via the same plugin's `get_currentuserinfo` endpoint and any cookie-authenticated controller action. Exploitation requires the PI-Media/json-api parent plugin to be installed and active with the Auth controller enabled, and a legitimate Administrator must have POSTed to `/api/auth/generate_auth_cookie/` within the preceding 24-hour cache TTL; the nominal HTTPS enforcement gate present in `Auth.php` is trivially bypassed by supplying `insecure=cool` as a request parameter.
Impact
Confidentiality: attacker obtains a valid admin session cookie, enabling full site access. Integrity: attacker can modify or delete content. Availability: not directly impacted. Defenders: site administrators, security teams, and plugin maintainers.
Remediation
Upgrade the JSON API Auth plugin to version 3.1.3 or later. If upgrading is not possible, disable or remove the Auth controller and any endpoints that expose authentication cookies. Clear existing transients cache and enforce HTTPS by removing the insecure parameter. Monitor for unexpected admin cookie generation and review access logs for anomalous activity.
Risk context
The vulnerability is rated critical with a CVSS v3 score of 9.8. EPSS is 0.00636, indicating a low probability of exploitation but a high impact if it occurs. Defenders should treat this as a high‑priority issue and apply mitigations promptly.
Affected products
- WordPress JSON API Auth plugin
- PI-Media/json-api
- WordPress
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- 0.00636