Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32420 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 06 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oauth Client Single Sign On Project
Oauth Client Single Sign On Project oauth Client Single Sign On Wordpress Wordpress wordpress |
|
| Vendors & Products |
Oauth Client Single Sign On Project
Oauth Client Single Sign On Project oauth Client Single Sign On Wordpress Wordpress wordpress |
Sat, 04 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts. | |
| Title | OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token() | |
| Weaknesses | CWE-347 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-06T14:16:32.877Z
Reserved: 2025-08-26T08:59:36.029Z
Link: CVE-2025-9485
Updated: 2025-10-06T14:14:16.651Z
Status : Awaiting Analysis
Published: 2025-10-04T03:15:38.780
Modified: 2025-10-06T14:56:47.823
Link: CVE-2025-9485
No data.
OpenCVE Enrichment
Updated: 2025-10-06T14:42:04Z
EUVD