Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-97637

JSON API Auth Cached Session Cookie Disclosure Allows Auth Bypass

JSON API Auth through 3.1.2 has a cached session cookie disclosure flaw allowing unauthenticated users to authenticate as any existing WordPress account.

cat cve-2026-97637.json
Vendor
JSON API Auth
Product
JSON API Auth WordPress Plugin (versions up to and including 3.1.2)
CVSS
9.8
EPSS (exploit probability)
0.6%
Status
patched
Published

CVE-2026-97637 is a CVSS 9.8 critical authentication bypass in the JSON API Auth WordPress plugin, affecting all versions up to and including 3.1.2. The vulnerability is a cached session cookie disclosure flaw: the plugin improperly stores and exposes session tokens in a way that allows an unauthenticated attacker to authenticate as any existing user account on the site, including administrator accounts.

A plugin providing a JSON authentication layer has authentication correctness as its core function. A bypass of this severity in that layer is a high-impact failure.

Site administrators should update through the WordPress admin dashboard. Deactivation is the recommended interim measure if an immediate update is not possible.

Source: NVD.