CVE-2026-65520
CRITICALWordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-65520. PoCs published by exploitintel.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-65520, an unauthenticated SQL injection vulnerability in the miniOrange WP OAuth Server WordPress plugin (<= 6.2.0). The exploit leverages a time-based blind SQLi via the OAuth2 token endpoint's `scope` parameter, bypassing WordPress magic quotes with JSON body parsing and tab characters.
Description
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2026-65520, an unauthenticated SQL injection vulnerability in the miniOrange WP OAuth Server WordPress plugin (<= 6.2.0). The exploit leverages a time-based blind SQLi via the OAuth2 token endpoint's `scope` parameter, bypassing WordPress magic quotes with JSON body parsing and tab characters.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L