plugin

Oauth Client Vulnerabilities

1 known security issue reported for the Oauth Client WordPress plugin. Most recent disclosed Jun 23, 2022.

1 critical

Running Oauth Client on your site? Check whether your installed version is affected.

Scan your site free

OAuth 2.0 client for SSO <= 1.11.3 - Authentication Bypass

critical

The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3. This is due to the plugin accepting a user supplied email address that is passed to wp_set_auth_cookie() with no further identity validation to verify that the email supplied belongs to the...

CVSS:
9.8
Affected:
up to 1.11.3
Fixed in:
1.11.4
Disclosed:
Jun 23, 2022

CVE-2022-34858 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database