CVE-2022-2133

MEDIUM

WordPress OAuth SSO <6.22.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/e76939ca-180f-4472-a26a-e0c36cfd32de

Scores

CVSS v3 5.3
EPSS 0.0099
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
miniorange/oauth_single_sign_on < 6.22.6
Published Jul 17, 2022
Tracked Since Feb 18, 2026