Extension WordPress
Vulnérabilités Simple JWT Login – Allows you to use JWT on REST endpoints.
Cette page rassemble les failles publiées pour Simple JWT Login – Allows you to use JWT on REST endpoints., leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple JWT Login – Allows you to use JWT on REST endpoints.
4 fiches
Simple JWT Login <= 3.6.6 – Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability…
*-3.6.6
3.6.7
10/07/2026
Simple JWT Login <= 3.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Simple JWT Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-3.6.4
3.6.5
22/09/2025
Simple JWT Login <= 3.2.0 – Cross-Site Request Forgery
The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user…
[*, 3.2.1)
3.2.1
18/10/2021
Simple JWT Login <= 3.2.1 – Insecure Password Creation
The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values,…
[*, 3.3.0)
3.3.0
13/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.