PT-2026-6677 · WordPress · Oauth Single Sign On – Sso

CVE-2025-10753

·

Publicado

2026-02-06

·

Atualizado

2026-02-06

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress versions prior to 6.26.15
Description The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is susceptible to unauthorized access. This is caused by missing capability checks and authentication verification within the OAuth redirect functionality, specifically through the oauthredirect option parameter. An unauthenticated attacker can set the global redirect URL option via the redirect url parameter if they have direct access to the site. The vulnerable functionality is accessible via the 'oauthredirect' option parameter.
Recommendations Update the OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress to version 6.26.15 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10753

Produtos afetados

Oauth Single Sign On – Sso