WordPress Plugin Vulnerabilities

WordPress + Microsoft Office 365 < 11.7 - JWT Signature Verification Bypass

Description

The plugin does not correctly verify JWT signatures, allowing attackers to forge tokens and bypass authentication and authorisation checks.

Affects Plugins

Fixed in 11.7

References

Miscellaneous

Original Researcher
Philip Åkesson
Submitter
Philip Åkesson
Submitter website
Verified
No

Timeline

Publicly Published
2020-10-02 (about 5 years ago)
Added
2020-10-02 (about 5 years ago)
Last Updated
2020-10-04 (about 5 years ago)

Other