First published: Sun Jul 17 2022(Updated: )
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange OAuth 2.0 Client for SSO | <6.22.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2133.
The severity of CVE-2022-2133 is medium with a severity value of 5.3.
The OAuth Single Sign On WordPress plugin before version 6.22.6 is affected by CVE-2022-2133.
CVE-2022-2133 allows attackers to log onto the site with just the knowledge of a user's email address.
To fix CVE-2022-2133, it is recommended to update the OAuth Single Sign On WordPress plugin to version 6.22.6 or higher.