The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-03-27T15:37:22.994Z

Updated: 2024-08-02T05:32:46.344Z

Reserved: 2023-02-28T14:35:38.935Z

Link: CVE-2023-1093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-03-27T16:15:09.833

Modified: 2024-11-21T07:38:26.673

Link: CVE-2023-1093

cve-icon Redhat

No data.