Impact
The vulnerability is an Authentication Bypass Using an Alternate Path or Channel, classified as CWE-288. It allows an attacker to trigger the password recovery flow without authenticating, effectively bypassing normal login controls and enabling unauthorized resetting or acquisition of account credentials, thereby compromising the confidentiality of user accounts.
Affected Systems
The miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress, supplied by miniOrange Security Software Pvt Ltd., is affected in all releases up through version 38.5.8. Sites running any of these versions are vulnerable if the password recovery functionality remains exposed.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote web access to the plugin’s password recovery endpoint; the exact attack vector is not explicitly defined, but it is inferred to be possible through normal web interfaces.
OpenCVE Enrichment