Impact
The TikTok WordPress plugin up to version 1.4.1 does not verify that a request is authorized before processing an OAuth sign‑in code supplied through the URL. An unauthenticated visitor can therefore cause the site to redeem any code of their choosing against the advertising platform, and the callback runs on every request because the code is loosely matched. This flaw allows an attacker to exploit the site’s OAuth credentials, potentially gaining unauthorized access to the advertising platform’s data or services.
Affected Systems
WordPress sites that use the TikTok plugin version 1.2.0 through 1.4.1 are affected. The vulnerability is present in the plugin’s OAuth redemption handling, which is exposed on any public page of the host site.
Risk and Exploitability
The vulnerability can be triggered by simply including a code parameter in a malicious URL that visitors can click or visit. Because it requires no authentication and is triggered on every request, it is remotely exploitable with low effort. No publicly available commercial exploits have been reported and the EPSS score is not available, but the flaw is not listed in the CISA KEV catalog. The lack of authorization check combined with loose code matching makes exploitation plausible for attackers seeking to abuse the site’s advertising credentials.
OpenCVE Enrichment