Impact
Unauthenticated broken authentication in the miniOrange OAuth Single Sign On – SSO (OAuth Client) WordPress plugin versions 7.0.0 and earlier allows attackers to log in as any user or bypass authentication entirely. The flaw is rooted in insufficient validation of OAuth claims, identified as CWE‑290. Successful exploitation would give an attacker unauthorized access to the WordPress site’s administrative functions, content, and potentially sensitive user data, leading to full site compromise.
Affected Systems
Vendors: miniOrange. Product: WordPress OAuth Single Sign On – SSO (OAuth Client) plugin. Affected versions: all releases up to and including 7.0.0. Updated versions start at 7.0.1 and contain the vulnerability fix.
Risk and Exploitability
CVSS score is 9.8, indicating a critical severity. EPSS score is not available, so current exploitation probability cannot be quantified. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely without authentication by manipulating the plugin’s SSO flow; the flaw does not require additional privileges or local access.
OpenCVE Enrichment