VYPR

WP OAuth Server

by WordPress

CVEs (9)

  • CVE-2022-34149CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

  • CVE-2026-65520CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

  • CVE-2026-82843CriSep 23, 2026
    risk 0.59cvss 9.0epss 0.00

    The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which…

  • CVE-2026-19715HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has…

  • CVE-2022-3926MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

  • CVE-2024-31253MedApr 10, 2024
    risk 0.31cvss 4.7epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.

  • CVE-2022-3892MedDec 5, 2022
    risk 0.31cvss 4.8epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

  • CVE-2022-4148MedMar 20, 2023
    risk 0.28cvss 4.3epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

  • CVE-2022-3894MedMar 20, 2023
    risk 0.28cvss 4.3epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and…