JSON API Auth Cached Session Cookie Disclosure Allows Auth Bypass
JSON API Auth through 3.1.2 has a cached session cookie disclosure flaw allowing unauthenticated users to authenticate as any existing WordPress account.
- Vendor
- JSON API Auth
- Product
- JSON API Auth WordPress Plugin (versions up to and including 3.1.2)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.6%
- Status
- patched
- Published
CVE-2026-97637 is a CVSS 9.8 critical authentication bypass in the JSON API Auth WordPress plugin, affecting all versions up to and including 3.1.2. The vulnerability is a cached session cookie disclosure flaw: the plugin improperly stores and exposes session tokens in a way that allows an unauthenticated attacker to authenticate as any existing user account on the site, including administrator accounts.
A plugin providing a JSON authentication layer has authentication correctness as its core function. A bypass of this severity in that layer is a high-impact failure.
Site administrators should update through the WordPress admin dashboard. Deactivation is the recommended interim measure if an immediate update is not possible.
Source: NVD.