Simple JWT Login Project maintains a focused WordPress authentication plugin centered on token-based user login, presenting a narrow but commonly extended codebase. The recurring exposure pattern involves cross-site request forgery and insufficient randomness in token generation, reflecting the cryptographic and session-handling demands of authentication middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Jwt Login Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24804HIGH The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as | Nov 17, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-24998HIGH The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shu | Dec 27, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Jwt Login Project.
Media articles that mention a CVE ID that affects a product developed by Simple Jwt Login Project — matched by CVE ID, not by vendor name.