CVE-2022-2133

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
17/07/2022
Last modified:
18/07/2022

Description

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:*:wordpress:*:* 6.22.6 (excluding)