CVE-2026-89027 | miniOrange JWT Authentication for WP REST APIs Plugin up to 4.7.x on WordPress downgrade
A vulnerability marked as critical has been reported in miniOrange JWT Authentication for WP REST APIs Plugin up to 4.7.x on WordPress. The affected element is an unknown function. This manipulation causes algorithm downgrade.
This vulnerability is tracked as CVE-2026-89027. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More