Sceawere
Vulnerability Detail
CVE-2026-39793UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Simple JWT Login Broken Authentication
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 16h ago
- Vendor
- Nicu Micle
- Product
- Simple JWT Login
- Attack Type
- CWE-288 Authentication Bypass Using an Alternate Path or Channel
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T09:17:52.237Z",
"pubdate": "2026-10-06T09:17:52.237Z",
"executiveSummary": "The Simple JWT Login plugin for WordPress, specifically version 4.0.0, is affected by a broken authentication vulnerability.\nThis flaw allows unauthorized entities to potentially authenticate as other users, including those with elevated privileges, due to improper validation of authentication tokens.\nThe vulnerability represents a critical security risk, as it bypasses standard WordPress authentication mechanisms, leading to complete account takeover or unauthorized access to sensitive application data.\nThe attack is remotely exploitable without requiring prior authentication, significantly lowering the barrier to entry for malicious actors.\nSuccessful exploitation grants an attacker the ability to interact with the application under the security context of the compromised user account, which may lead to full administrative compromise of the WordPress installation.",
"technicalDetails": "The vulnerability resides within the authentication logic of the Simple JWT Login plugin version 4.0.0. The root cause is an inadequate implementation of JWT (JSON Web Token) verification during the authentication workflow.\nIn the affected version, the plugin fails to properly validate the integrity and authenticity of the provided JWTs when processing login requests. Specifically, the verification process does not sufficiently enforce signature validation or expiry checks, allowing an attacker to craft or manipulate tokens to impersonate legitimate users.\nThe attack flow commences when an unauthenticated attacker sends a specially crafted request to the plugin's authentication endpoint. By injecting a forged or malformed JWT into the appropriate header or request body, the attacker exploits the lack of robust cryptographic validation. Because the plugin does not verify the token's origin or integrity, it incorrectly maps the claims within the malicious JWT to a user record in the WordPress database.\nIf the 'sub' (subject) claim in the JWT is modified to match a target user's ID or username, the plugin erroneously considers the session authenticated. This bypasses the standard authentication routines provided by the WordPress core, effectively granting the attacker the permissions associated with the targeted user account.\nThis vulnerability is classified as broken authentication, as the plugin fails to maintain the security boundary required for secure session management. The lack of cryptographic enforcement enables remote code execution or unauthorized data modification if the compromised user possesses administrative capabilities. The vulnerability exists within the request processing logic of the plugin, and exposure is limited to the endpoint exposed by the Simple JWT Login plugin. Because the authentication process is entirely decoupled from the intended secure verification flow, no specific privileges are required to initiate this attack, making it highly dangerous in publicly accessible environments."
}