Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-97637 2026-10-02

JSON API Auth WordPress Plugin Flaw Leaks Administrator Session Cookies (CVE-2026-97637)

"CVE-2026-97637 is a critical authentication bypass (CVSS 9.8) in the JSON API Auth plugin for WordPress, versions up to and including 3.1.2. Under certain conditions, an unauthenticated attacker can retrieve a cached…"

CVE-2026-97637 is a critical authentication bypass (CVSS 9.8) in the JSON API Auth plugin for WordPress, versions up to and including 3.1.2. Under certain conditions, an unauthenticated attacker can retrieve a cached Administrator session cookie and use it to log in as the site Administrator.

What Is It

The flaw is an authentication bypass through disclosure of a cached session cookie (CWE-287). JSON API Auth depends on the PI-Media/json-api parent plugin. That parent plugin caches controller results in transients. The cache key is built only from the URI and query string, so it ignores the HTTP method and the POST body.

The plugin's generate_auth_cookie() endpoint puts a live WordPress logged_in cookie, created by wp_generate_auth_cookie(), directly in its JSON response. When an Administrator POSTs to /api/auth/generate_auth_cookie/, that response is cached. Any later unauthenticated GET request to the same URI then receives the cached response, including the Administrator's cookie.

The HTTPS check in Auth.php does not stop this. Adding insecure=cool as a request parameter bypasses it.

Why It Matters

With the stolen cookie, an attacker can fully authenticate as the site Administrator. That includes the plugin's get_currentuserinfo endpoint and any controller action that accepts cookie authentication. Wordfence scored it 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): it can be exploited over the network, with low complexity, and needs no privileges or user interaction.

Exploitation does depend on conditions. The PI-Media/json-api parent plugin must be installed and active with the Auth controller enabled. A legitimate Administrator must also have POSTed to /api/auth/generate_auth_cookie/ within the previous 24 hours, which is the cache lifetime.

This CVE has no CISA KEV entry, so active exploitation is not confirmed in the supplied data.

What's Vulnerable

Patch Status

The NVD record does not name a fixed version. It references a WordPress plugin Trac changeset for json-api-auth, but the supplied data does not confirm that it fixes this flaw. The NVD status is "Deferred," and there is no CISA KEV required action or due date. Administrators running JSON API Auth 3.1.2 or earlier should check the Wordfence advisory for remediation guidance. They should also review whether the plugin and its json-api parent need to stay enabled.

Sources