Impact
The WP OAuth Server plugin, in versions prior to 6.3.1, writes debug logs that contain OAuth tokens, authorization codes, and user records including password hashes to a fixed file path that is publicly accessible. This allows any unauthenticated user to read the log and obtain sensitive data, resulting in a confidentiality breach. The description does not state the exact access method, but it can be inferred that a simple HTTP request to the log file URL will expose the information.
Affected Systems
All installations of the WP OAuth Server (Login with WordPress) WordPress plugin running any version older than 6.3.1 are affected. No additional vendors or products are listed.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users and does not require authentication or privileged access; thus it poses a high risk to confidentiality. No official CVSS score or EPSS value is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may not yet be widespread. However, the ease of exploitation and the sensitivity of the exposed data mean that the risk remains significant until the vulnerability is mitigated.
OpenCVE Enrichment