WP OAuth Server (OAuth Authentication)

WP OAuth Server (OAuth Authentication) has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2024; all 7 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2023 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (43%). Other recurring categories include Cross-Site Scripting, Incorrect Authorization.

Every one of the 7 issues recorded for WP OAuth Server (OAuth Authentication) has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, most of them (4) reported by István Márton. WP OAuth Server (OAuth Authentication) is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

7

Get automatic notifications for all WP OAuth Server (OAuth Authentication) vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2015-9435

WP OAuth Server (OAuth Authentication) < 3.1.5 - Pseudorandom Number Generation

Read the full analysis

Vulnerability Records

7 records
WP OAuth Server (OAuth Authentication) banner
Latestv4.5.1

WP OAuth Server (OAuth Authentication)

Jayson T Cote

Author

Jayson T Cote

3.8(41)
76/100
Last Updated
2026-08-14 (1mo ago)
Active Installs
3,000+
Downloads
186,067
Requires WP
4.7.2+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2013-03-21 (14y ago)

Connect your app to WordPress or use SSO to connect multiple websites with the same username and passwords. No 3rd party servers are needed with WP OAuth Server. Everything you need is in this plugin. Features WP REST API Authentication. Provides ability to make authorized calls to protected REST API endpoints. WP REST API Lock Down. Prevent any calls to the REST API unless authorized Unlimited OAuth 2.0 Clients Support for Implicit Flow Built-In Resource Server Automated Authorization Flow (User does not have to see authorization screen) Easily Extend/ Modify the Endpoints OAuth 2.0 PKCE Modern and Legacy JWT authorization support. OAuth 2.0 JSON Web Token Support Supported Grant Types Authentication Code w/Implicit User Credentials (Pro) Client Credentials (Pro) Refresh Token (Pro) OpenID Connect (Pro) OpenID Discovery Public Clients (Pro) Public Client Proof of Key Exchange (PKCE) Supports Connecting any Custom Mobile and Desktop Application to WordPress’s Backend. Any software or web platform utilizing OAuth 2.0. Allows RocketChat to use WordPress as a Backend. Connects Moodle LMS and use WordPress users. Alexa Skills Authentication Tribe.so Community OAuth 2 SSO Support How to Use Visit https://wp-oauth.com/support/documentation/ for detailed documentation on installing, configuring and using WordPress OAuth Server. Licensing WP OAuth Server is free to use. Please support the project by licensing. You can view more information at https://wp-oauth.com. Minimum Requirements PHP 7.4 or greater (latest version recommended) OpenSSL installed and enabled if you plan on using OpenID Connect Other Information NOTE: As of 3.0.0, there are no backward compatibility for any version older than 3.0.0 NOTE: Due to IIS’s inability play nice, WP OAuth Server may work but is very limited for Windows OS. Support Support requests should be made by opening a support request at https://wp-oauth.com/support/submit-ticket/.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C