Known vulnerabilities in Simple JWT Login – Allows you to use JWT on REST endpoints.
Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.
5Reported vulnerabilities
8.8Highest CVSS score
3.6.8Latest version
4,000+Active installs
What to do now
Update Simple JWT Login – Allows you to use JWT on REST endpoints. to 3.6.8 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2021-24804 | High | 0.6% | Before 3.2.1 | 3.2.1 |
November 17, 2021 |
| CVE-2026-14262 | High | 0.7% | 0 to 3.6.6 (inclusive) | 3.6.7 |
July 11, 2026 |
| CVE-2021-24998 | High | 1.2% | Before 3.3.0 | 3.3.0 |
December 27, 2021 |
| CVE-2026-19714 | High | 0.3% | Before 3.6.8 | 3.6.8 |
August 20, 2026 |
| CVE-2025-58648 | Medium | 0.2% | 3.6.4 and earlier | 3.6.5 |
September 22, 2025 |