ZeroHour

CVE-2021-24998

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used for cryptographic purposes" according to PHP's documentation.

Vendors
simple jwt login project
Products
simple jwt login
Ecosystems
WordPress
Weakness
CWE-330
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.