CVE-2026-14262
HIGHSimple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-14262. PoCs published by incogbyte.
AI-analyzed exploit summary Exploits an authentication bypass to privilege escalation in Simple JWT Login <= 3.6.6 by injecting a malicious `payload` parameter during JWT generation, allowing an attacker to impersonate any user (e.g., Administrator) via a crafted JWT. The flaw stems from improper sanitization of attacker-controlled payload claims in the JWT signing process.
Description
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an Administrator by injecting a target administrator's email address into the `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/autologin` endpoint to obtain a fully authenticated session as that administrator.
Exploits (1)
Exploits an authentication bypass to privilege escalation in Simple JWT Login <= 3.6.6 by injecting a malicious `payload` parameter during JWT generation, allowing an attacker to impersonate any user (e.g., Administrator) via a crafted JWT. The flaw stems from improper sanitization of attacker-controlled payload claims in the JWT signing process.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H