High severity7.5NVD Advisory· Published Sep 26, 2022· Updated Jun 17, 2026
CVE-2022-3119
CVE-2022-3119
Description
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<3.0.4+ 1 more
- (no CPE)range: <3.0.4
- (no CPE)range: <3.0.4
- cpe:2.3:a:oauth_client_single_sign_on_project:oauth_client_single_sign_on:*:*:*:*:*:wordpress:*:*Range: <3.0.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/55b83cee-a8a5-4f9d-a976-a3eed9a558e5nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.