WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.4.0
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31253 on NVD →
OAuth Server <= 4.3.3 - Open Redirect
medium
The WP OAuth Server (OAuth Authentication) plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.3.3. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successf...
- CVSS:
- 5.4
- Affected:
- up to 4.3.3
- Fixed in:
- 4.4.0
- Disclosed:
- Apr 5, 2024
CVE-2024-31253 on NVD →
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.3.0
unknown
[en] The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Mar 20, 2023
CVE-2022-4148 on NVD →
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.2.5
unknown
[en] The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
- Affected:
- up to 4.2.5
- Fixed in:
- 4.2.5
- Disclosed:
- Mar 20, 2023
CVE-2022-3894 on NVD →
WP OAuth Server <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Post Deletion (wo_ajax_remove_client)
medium
The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the wo_ajax_remove_clientfunction. This makes it possible for unauthenticated attackers to delete arbitrary posts, via a forged request gr...
- CVSS:
- 6.5
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.5
- Disclosed:
- Feb 21, 2023
CVE-2022-3894 on NVD →
WP OAuth Server <= 4.2.5 - Authenticated (Subscriber+) Arbitrary Client Deletion (wo_ajax_remove_client)
medium
The WP OAuth Server plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wo_ajax_remove_client() function in versions up to, and including, 4.2.5. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete arbitrary clie...
- CVSS:
- 4.3
- Affected:
- up to 4.2.5
- Fixed in:
- 4.3.0
- Disclosed:
- Feb 21, 2023
CVE-2022-4148 on NVD →
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.3.0
unknown
Deactivate and delete. This plugin has been closed as of January 18, 2023 and is not available for download. This closure is temporary, pending a full review.
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress OAuth Server Plugin. This could allow a malicious actor to forc...
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 27, 2023
WP OAuth Server (OAuth Authentication) <= 4.2.5 -Cross-Site Request Forgery
medium
The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.5. This is due to missing or incorrect nonce validation on several of its AJAX actions like wo_ajax_remove_self_generated_token. This makes it possible for unauthenticated attackers to remove gener...
- CVSS:
- 5.4
- Affected:
- up to 4.2.5
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 26, 2023
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.3.0
unknown
The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.5. This is due to missing or incorrect nonce validation on several of its AJAX actions like wo_ajax_remove_self_generated_token. This makes it possible for unauthenticated attackers to remove gener...
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 26, 2023
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.2.2
unknown
[en] The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- Dec 5, 2022
CVE-2022-3926 on NVD →
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 4.2.2
unknown
[en] The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- Dec 5, 2022
CVE-2022-3892 on NVD →
WP OAuth Server (OAuth Authentication) <= 4.2.5 - Cross-Site Request Forgery
high
The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.5. This is due to missing nonce validation on one the wo_regenerate_secret() function. This makes it possible for unauthenticated attackers to regenerate client secrets, via forged request granted...
- CVSS:
- 8.8
- Affected:
- up to 4.2.5
- Fixed in:
- 4.3.0
- Disclosed:
- Nov 10, 2022
CVE-2022-3926 on NVD →
WP OAuth Server (OAuth Authentication) <= 4.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP OAuth Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client ID parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 5.5
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Nov 8, 2022
CVE-2022-3892 on NVD →
WP OAuth Server (OAuth Authentication) [oauth2-provider] < 3.1.5
unknown
[en] The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Sep 26, 2019
CVE-2015-9435 on NVD →
WP OAuth Server (OAuth Authentication) < 3.1.5 - Pseudorandom Number Generation
critical
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
- CVSS:
- 9.8
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Aug 12, 2015
CVE-2015-9435 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database