cleantalk
Vulnerabilities and Security Researches

WordPress + Microsoft Office 365 / Azure AD | LOGIN, CVE-2020-26511

CVE, Research URL

CVE-2020-26511

Published on
Oct 02, 2020
Research Description
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Affected versions
max 11.7.
Status
vulnerable