OAuth SSO Bypass

CRITICAL (9.8)

Threat Intelligence

Low Risk
EPSS Score: 0.48% chance of exploitation (percentile: 64%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is a popular extension that allows users to access their accounts without entering credentials. However, this vulnerability allows attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or create arbitrary subscriber-level accounts.

Am I affected?

Specific version info not stated in the advisory.

How to fix

  1. Upgrade to WordPress 6.27 or later.
  2. For immediate mitigation:
  3. Restrict network access to your WordPress instance (firewall it from the public internet)
  4. Audit admin account activity for suspicious access patterns
  5. Monitor for unauthorized token creation