The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-07-17T10:36:17

Updated: 2022-07-17T10:36:17

Reserved: 2022-06-20T00:00:00


Link: CVE-2022-2133

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-07-17T11:15:08.837

Modified: 2022-07-18T11:23:21.447


Link: CVE-2022-2133

JSON object: View

cve-icon Redhat Information

No data.

CWE