Back to search
CVE-2021-24804
Published: Nov 17, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Simple JWT Login – Login and Register to WordPress using JWT | affected 3.2.1 - < 3.2.1 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now