Simple Single Sign On <= 4.1.1 - Insecure OAuth Implementation to Authentication Bypass
highThe Simple Single Sign On plugin for WordPress is vulnerable to authorization bypass due to insecurely configured OAuth in versions up to, and including, 4.1.1 which allows attackers to retrieve client access_tokens that can be used to authenticate to a vulnerable site. This makes it possible unauthenticated attackers...
- CVSS:
- 8.1
- Affected:
- up to 4.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2022