First published: Mon Aug 22 2022(Updated: )
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange OAuth 2.0 Client for SSO | <1.11.4 |
Update to 1.11.4 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34858 is critical with a score of 9.8.
The vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected WordPress site.
CVE-2022-34858 affects versions up to and including 1.11.3 of the miniOrange OAuth 2.0 client for SSO plugin for WordPress.
Yes, updating the miniOrange OAuth 2.0 client for SSO plugin to version 1.11.4 or higher will fix the vulnerability.
More information about CVE-2022-34858 can be found at the following references: [Reference 1](https://lana.codes/lanavdb/df23b19f-4134-41d3-8cb3-9d44189b461b?_s_id=cve), [Reference 2](https://patchstack.com/database/vulnerability/oauth-client/wordpress-oauth-2-0-client-for-sso-plugin-1-11-3-authentication-bypass-vulnerability?_s_id=cve)