vulnerability

WordPress Plugin: jwt-auth: CVE-2021-46743: Access of Resource Using Incompatible Type ('Type Confusion')

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Nov 11, 2022
Added
May 15, 2025
Modified
May 15, 2025

Description

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. This may or may not be exploitable in WordPress plugins and themes using the library.

Solution

jwt-auth-plugin-cve-2021-46743
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.