CVE WATCH / VULNERABILITY DETAIL
CVE-2026-97637
CRITICALCVSS 9.8NVD feed
Published 2 October 2026 · tracked since 2 October 2026
Description
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-104606 MEDIUM 6.3
- CVE-2026-94541 CRITICAL 9.8
- CVE-2026-87920 HIGH 7.2
- CVE-2026-103552 HIGH 7.3
- CVE-2026-97663 HIGH 7.2
- CVE-2026-97338 MEDIUM 6.4
- CVE-2026-97342 HIGH 7.2
- CVE-2026-97634 MEDIUM 6.5
- CVE-2026-97641 HIGH 7.2
- CVE-2026-96566 HIGH 7.2