OAuth 2.0 client for SSO <= 1.11.3 - Authentication Bypass
criticalThe OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3. This is due to the plugin accepting a user supplied email address that is passed to wp_set_auth_cookie() with no further identity validation to verify that the email supplied belongs to the...
- CVSS:
- 9.8
- Affected:
- up to 1.11.3
- Fixed in:
- 1.11.4
- Disclosed:
- Jun 23, 2022