Unrated severityNVD Advisory· Published Sep 26, 2022· Updated May 21, 2025
OAuth client Single Sign On for WordPress < 3.0.4 - Unauthenticated Settings Update to Authentication Bypass
CVE-2022-3119
Description
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.0.4+ 1 more
- (no CPE)range: <3.0.4
- (no CPE)range: <3.0.4
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/55b83cee-a8a5-4f9d-a976-a3eed9a558e5mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.