Impact
The plugin contains an authentication method downgrade vulnerability that permits an attacker to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification, thereby allowing unauthenticated access. This flaw can be leveraged for unthrottled username enumeration and password guessing attacks, providing a foothold for broader compromise.
Affected Systems
The affected product is the miniOrange JWT Authentication for WP REST APIs plugin for WordPress, versions prior to 4.8.0. Any site that has this plugin token authentication is susceptible until the plugin is updated to 4.8.0 or later.
Risk and Exploitability
The flaw has a CVSS score of 6.9, indicating a moderate severity. The EPSS score of < 1% suggests a low probability of exploitation, and it is not listed in CISA KEV. The likely attack vector is a remote attacker sending crafted HTTP GET requests to a public WordPress site, using the downgrade parameter to exploiting error codes and the lack of rate limiting to enumerate users and attempt credential guessing. No specific access privilege is required for initial exploitation, but successful enumeration can facilitate further attacks.
OpenCVE Enrichment