The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-05T16:50:35.245Z

Updated:

Reserved: 2022-11-10T13:13:50.936Z


Link: CVE-2022-3926

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-12-05T17:15:10.733

Modified: 2023-11-07T03:51:58.403


Link: CVE-2022-3926

JSON object: View

cve-icon Redhat Information

No data.

CWE