First published: Mon Aug 22 2022(Updated: )
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP OAuth Server | <=3.0.4 |
Update to 4.0.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34149 is an authentication bypass vulnerability in the miniOrange WP OAuth Server plugin version 3.0.4 and below for WordPress.
CVE-2022-34149 is classified as a critical vulnerability with a severity score of 9.8 out of 10.
The miniOrange WP OAuth Server plugin versions up to and including 3.0.4 for WordPress are affected by CVE-2022-34149.
CVE-2022-34149 falls under the CWE categories 264 (Permissions, Privileges, and Access Controls) and 287 (Improper Authentication).
Yes, you can find references for CVE-2022-34149 at the following URLs: [Link 1](https://lana.codes/lanavdb/6d794d65-d44b-4099-94c5-3dd2995b218c?_s_id=cve) and [Link 2](https://patchstack.com/database/vulnerability/miniorange-oauth-20-server/wordpress-wp-oauth-server-plugin-3-0-4-authentication-bypass-vulnerability?_s_id=cve).