CVE-2026-97288: WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Affected Software
1 affected component
WordPress OAuth Server<=4.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OAuth Server pluginto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which sites are exposed to this issue?
Sites using the WordPress OAuth Server plugin version 4.5.1 or earlier are affected. Exploitation requires Contributor-level access, so sites that do not grant or expose Contributor accounts have a reduced practical exposure.
2
What access and interaction does exploitation require?
An attacker must authenticate with low-privileged Contributor credentials and induce user interaction. The reported impact includes limited confidentiality, integrity, and availability effects across a changed security scope.