PT-2026-73124 · WordPress · Simple Jwt Login

·

CVE-2026-19714

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Simple JWT Login versions prior to 3.6.8
Description The plugin fails to validate the audience of accepted Google identity tokens. This allows unauthenticated users to authenticate as any user, including administrators, by providing a token containing the target user's email address.
Recommendations Update Simple JWT Login to version 3.6.8 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19714

Affected Products

Simple Jwt Login