OAuth Single Sign On – SSO (OAuth Client) <= 6.22.5 - Authentication Bypass
2022-06-27 00:00
István MártonStrategic Overview
StatusPatched in 6.22.6
Affected PluginOAuth Single Sign On – SSO (OAuth Client)
Affected Version
<= 6.22.5CVSS8.1High
CVE
CVE-2022-2133Vulnerability Overview
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
Technical Analysis
REMEDIATION: Update to version 6.22.6, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C