CVE-2026-14262
nicu_m Simple JWT Login – Allows you to use JWT on REST endpoints.
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subs...
- CVSS
- 8.8
- EPSS
- 0.38% 31.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11