CVE-2026-97274: WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Affected Software
1 affected component
miniOrange OAuth Single Sign On – SSO (OAuth Client)<=7.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OAuth Single Sign On – SSO (OAuth Client)to a version that resolves this vulnerability.Fixed in 7.1.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and network-accessible, so an attacker does not need an account or user interaction to attempt exploitation.
2
Which plugin versions are affected?
Versions 7.1.2 and earlier of the OAuth Single Sign On – SSO (OAuth Client) plugin are affected.
3
What is the potential impact?
The reported severity is critical, with high impact to confidentiality, integrity, and availability. Successful exploitation could allow an attacker to bypass an affected security control.