Description
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Exploits (1)
References (2)
Core 2
Core References
Third Party Advisory vdb-entry
https://patchstack.com/database/vulnerability/miniorange-login-with-eve-online-google-facebook/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-6-23-3-broken-authentication-vulnerability?_s_id=cve
Exploit third-party-advisory
technical-description
https://lana.codes/lanavdb/071fa6eb-2e54-43a1-b37f-1e562988b7d4?_s_id=cve
Scores
CVSS v3
8.8
EPSS
0.0019
EPSS Percentile
39.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (2)
miniOrange/OAuth Single Sign On – SSO (OAuth Client)
< 6.23.3
miniorange/oauth_single_sign_on
< 6.23.4
Published
Jul 18, 2023
Tracked Since
Feb 18, 2026