CyberRota Analysis
AI-GeneratedThe Simple JWT Login plugin for WordPress versions prior to 3.6.8 is vulnerable due to inadequate validation of Google identity tokens, enabling unauthenticated users to impersonate any user, including administrators, based on the email address contained in the token. This flaw poses a significant security risk for any WordPress site utilizing this plugin with Google sign-in enabled. WordPress administrators using this plugin should prioritize immediate updates to mitigate potential unauthorized access.
Original NVD Description
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.