External risk intelligence

JSON API Auth Plugin Authentication Bypass via Cached Session Cookie Disclosure

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-97637

The vulnerability resides in a WordPress plugin that implements a JSON API. WordPress sites are frequently deployed as public-facing web applications, and API endpoints are commonly exposed to the internet to facilitate external integrations, making this component a likely part of the internet-facing attack surface.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves a vulnerability in a WordPress plugin that handles authentication. It allows unauthorized users to gain administrative access by exploiting a flaw in how user session information is cached. This could potentially lead to a complete compromise of the affected website.

  • Admin access can be stolen via cached sessions.
  • Ensures a critical component is properly secured.
  • Verify relevance and confirm exposure status.

Attack Path

How an attacker could exploit the issue

An attacker can gain administrator privileges by exploiting how the JSON API Auth plugin caches responses. If an administrator has recently used a specific authentication endpoint, the plugin might inadvertently store a valid session cookie. An unauthenticated attacker can then request this cached information, retrieve the administrator's session cookie, and use it to impersonate the administrator, granting them full control over the WordPress site.

  • Requires parent plugin and auth controller.
  • Attacker retrieves cached session cookie.
  • Full administrator access.

Live Threat

Current exploitation, exposure, and threat context

When the PI-Media/json-api parent plugin is installed and active, an unauthenticated attacker could obtain a valid administrator session cookie. This could occur if a legitimate administrator previously posted to `/api/auth/generate_auth_cookie/` within the last 24 hours, and the attacker can then use this cookie to authenticate as the site administrator.

  • Administrator session cookies.
  • Cached API responses can be disclosed.
  • Full administrative control of the site.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are most likely responsible for addressing this vulnerability in the WordPress JSON API Auth plugin. The first practical step is to identify all WordPress instances utilizing the PI-Media/json-api parent plugin with the Auth controller enabled. Confirm if these instances are internet-reachable and handle sensitive data or administrative functions, then identify the specific site owner for prioritization and remediation planning.

  • Identify WordPress sites with the plugin.
  • Verify exposure and business criticality.
  • Plan remediation with site owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JSON API Auth plugin for WordPress?

It is an add-on for WordPress websites that integrates with the PI-Media/json-api framework. Developers use it to manage authentication tasks via a JSON-based API, enabling external services or applications to interact with the site's user accounts and administrative functions programmatically.

What does CWE-287 mean for this CVE?

CWE-287 refers to Improper Authentication. In this specific case, the flaw allows an attacker to bypass security checks entirely. Because the plugin caches responses incorrectly, it treats an unauthenticated request as if it were a valid, authenticated session, effectively handing the site's session keys to anyone who requests them.

How does an attacker trigger this vulnerability?

An attacker needs an administrator to have recently used the authentication endpoint. If that happens, the system caches the resulting session cookie. The attacker then requests the same URI. The bug is not triggered if the cache has expired or if the required parent plugin and Auth controller are not active.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because WordPress sites with JSON APIs are typically deployed as public-facing web applications. Since these endpoints are often internet-facing to support integrations, your site may be reachable by attackers regardless of whether you intended the API to be public.

What are the first steps to secure my site?

Begin by auditing your WordPress environment to see if the PI-Media/json-api parent plugin is active with the Auth controller enabled. If found, determine if the site is internet-facing. Coordinate with site owners to restrict access to these API endpoints or disable the affected controller until you can verify a secure configuration.

References