Rapid7

vulnerability

WordPress Plugin: jwt-auth: CVE-2021-46743: Access of Resource Using Incompatible Type ('Type Confusion')

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Nov 11, 2022
Added
May 15, 2025
Modified
Apr 30, 2026

Description

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. This may or may not be exploitable in WordPress plugins and themes using the library.

Solution

jwt-auth-plugin-cve-2021-46743
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.