Known vulnerabilities in JWT Authentication for WP REST APIs
Secure and protect WordPress REST API from unauthorized access using JWT token, Basic Authentication, API Key, OAuth 2, or external token.
2Reported vulnerabilities
8.8Highest CVSS score
4.6.0Latest version
20,000+Active installs
What to do now
Update JWT Authentication for WP REST APIs to 3.6.4 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-45073 | High | 0.3% | 2.4.0 and earlier | 2.4.1 |
November 18, 2022 |
| CVE-2025-39545 | Medium | 0.5% | 0 to 3.6.3 (inclusive) | 3.6.4 |
April 16, 2025 |