Description
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51509 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-26T18:59:29.135Z
Reserved: 2022-11-28T10:34:15.653Z
Link: CVE-2022-4148
Updated: 2024-08-03T01:27:54.502Z
Status : Modified
Published: 2023-03-20T16:15:11.483
Modified: 2025-02-26T19:15:14.460
Link: CVE-2022-4148
No data.
OpenCVE Enrichment
No data.
EUVD