WordPress Plugin Vulnerabilities
WordPress + Microsoft Office 365 < 11.7 - JWT Signature Verification Bypass
Description
The plugin does not correctly verify JWT signatures, allowing attackers to forge tokens and bypass authentication and authorisation checks.
Affects Plugins
References
Miscellaneous
Original Researcher
Philip Åkesson
Submitter
Philip Åkesson
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-10-02 (about 5 years ago)
Added
2020-10-02 (about 5 years ago)
Last Updated
2020-10-04 (about 5 years ago)