The Simple JWT Login WordPress... CVE-2021-24804

6.8 AV AC AU C I A
发布: 2021-11-17
修订: 2024-11-21

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息