The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.wpo365.com/change-log/ | release notes vendor advisory |
https://plugins.trac.wordpress.org/changeset/2388992/ | third party advisory patch |
https://wordpress.org/plugins/wpo365-login/#developers | third party advisory product |
https://wpvulndb.com/vulnerabilities/10418 | third party advisory |