The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-23380 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 19 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-19T20:16:48.586Z
Reserved: 2023-02-28T14:35:38.935Z
Link: CVE-2023-1093
Updated: 2024-08-02T05:32:46.344Z
Status : Modified
Published: 2023-03-27T16:15:09.833
Modified: 2025-02-19T21:15:12.523
Link: CVE-2023-1093
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD