plugin

Jwt Auth Vulnerabilities

1 known security issue reported for the Jwt Auth WordPress plugin. Most recent disclosed Nov 11, 2022.

1 critical

Running Jwt Auth on your site? Check whether your installed version is affected.

Scan your site free

Firebase PHP-JWT < 6.0.0 - Algorithm Confusion

critical

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. This may or may not be exploitable in WordPress plugins and th...

CVSS:
9.1
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Nov 11, 2022

CVE-2021-46743 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database