First published: Fri Oct 02 2020(Updated: )
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wpo365 Wordpress + Azure Ad / Microsoft Office 365 | <11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26511 is considered a high severity vulnerability due to the potential for authentication bypass.
To fix CVE-2020-26511, update the wpo365-login plugin to version 11.7 or later.
CVE-2020-26511 is an authentication bypass vulnerability.
Versions of the wpo365-login plugin prior to 11.7 are affected by CVE-2020-26511.
If exploited, CVE-2020-26511 allows unauthorized access to users' accounts by bypassing authentication.