Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-14262: WordPress Simple JWT Login Plugin Allows Attackers to Escalate Privileges

CVE-2026-14262 CVE-2026-14262
Summary

A security flaw in the WordPress Simple JWT Login Plugin allows attackers to bypass authentication and gain administrator privileges. This affects all versions of the plugin up to 3.6.6. To stay secure, update the plugin to the latest version or remove it if it's no longer needed.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
nicu_m simple jwt login – allows you to use jwt on rest endpoints. <= 3.6.6
Original title
Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
Original description
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an Administrator by injecting a target administrator's email address into the `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/autologin` endpoint to obtain a fully authenticated session as that administrator.
nvd CVSS3.1 8.8
Vulnerability type
CWE-269 Improper Privilege Management
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026