The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-11-17T10:15:43

Updated: 2024-08-03T19:42:17.213Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-11-17T11:15:07.990

Modified: 2021-11-19T17:47:23.467

Link: CVE-2021-24804

cve-icon Redhat

No data.