The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/1e13b9ea-a3ef-483b-b967-6ec14bd6d54d | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2023-03-27T15:37:22.994Z
Updated: 2023-03-27T15:37:22.994Z
Reserved: 2023-02-28T14:35:38.935Z
Link: CVE-2023-1093
JSON object: View
NVD Information
Status : Modified
Published: 2023-03-27T16:15:09.833
Modified: 2023-11-07T04:02:29.463
Link: CVE-2023-1093
JSON object: View
Redhat Information
No data.
CWE
No CWE.