Impact
The WP OAuth Server plugin, in all versions prior to 6.3.1, writes debug logs that contain OAuth tokens, authorization codes, and user records including password hashes to a fixed file path that is publicly accessible. This flaw allows any unauthenticated user to read the log via an HTTP request and acquire sensitive data, resulting in a confidentiality breach.
Affected Systems
All installations of the WP OAuth Server (Login with WordPress) WordPress plugin running a version older than 6.3.1 are affected. No other vendors or products are listed.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users without the need for privileged access, posing a high risk to confidentiality. The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog, implying that active exploitation may not yet be widespread, but the ease of exploitation and the sensitivity of the exposed data keep the risk significant until mitigated.
OpenCVE Enrichment