CVE-2022-34858: WordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerability
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34858?
The severity of CVE-2022-34858 is critical with a score of 9.8.
How does the authentication bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress work?
The vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected WordPress site.
What software versions are affected by CVE-2022-34858?
CVE-2022-34858 affects versions up to and including 1.11.3 of the miniOrange OAuth 2.0 client for SSO plugin for WordPress.
Are there any fixes available for CVE-2022-34858?
Yes, updating the miniOrange OAuth 2.0 client for SSO plugin to version 1.11.4 or higher will fix the vulnerability.
Where can I find more information about CVE-2022-34858?
More information about CVE-2022-34858 can be found at the following references: [Reference 1](https://lana.codes/lanavdb/df23b19f-4134-41d3-8cb3-9d44189b461b?_s_id=cve), [Reference 2](https://patchstack.com/database/vulnerability/oauth-client/wordpress-oauth-2-0-client-for-sso-plugin-1-11-3-authentication-bypass-vulnerability?_s_id=cve)