Impact
The OAuth Single Sign On WordPress plugin fails to verify the identity assertion returned in the Steam OpenID single sign‑on flow. This allows an unauthenticated attacker to obtain a valid session for any existing non‑administrator user or to create new user accounts without permission. The result is unauthorized access that can compromise confidentiality, allow data manipulation, or provide a foothold for further attacks within the site.
Affected Systems
The OAuth Single Sign On WordPress plugin before version 7.0.1 is vulnerable. The affected plugin is used on WordPress sites that support Steam OpenID authentication. Versions 7.0.1 and later include the proper verification and are not affected.
Risk and Exploitability
Because no credentials are required and the flaw resides in the authentication process itself, an attacker can mount the exploit remotely by sending a forged OpenID assertion. The lack of EPSS data does not lower the overall risk, and the KEV not listing does not guarantee absence of exploitation. The severity of an unauthenticated takeover remains high, and prompt action is advised.
OpenCVE Enrichment