Simple JWT Login – Login and Register to WordPress using JWT, CVE-2021-24998
- CVE, Research URL
- Home page URL
-
Security reports for Simple JWT Login – Login and Register to WordPress using JWT
- Published on
- Dec 27, 2021
- Research Description
- The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used for cryptographic purposes" according to PHP's documentation.
- Affected versions
-
max 3.3.0.
- Status
-
vulnerable