First published: Mon Dec 05 2022(Updated: )
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP OAuth Server | <3.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3926 is considered high due to the potential for attackers to compromise admin secrets.
To fix CVE-2022-3926, update the WP OAuth Server plugin to version 3.4.2 or later.
CVE-2022-3926 affects all versions of the WP OAuth Server plugin before 3.4.2.
CVE-2022-3926 can enable attackers to force logged-in admins to regenerate OAuth client secrets.
Yes, CVE-2022-3926 poses a risk to user authentication by allowing attackers to manipulate secret regeneration.