PT-2022-14844 · WordPress · The Simple Single Sign On

·

CVE-2022-2083

·

Published

2022-09-05

·

Updated

2023-08-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Simple Single Sign On WordPress plugin versions through 4.1.0
Description The issue allows attackers to gain unauthorized access to the site by leaking its OAuth client secret. This could potentially lead to malicious activities.
Recommendations For The Simple Single Sign On WordPress plugin versions through 4.1.0, update to a version later than 4.1.0 to prevent the leak of the OAuth client secret. As a temporary workaround, consider restricting access to the OAuth functionality until a patch is available.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2083

Affected Products

The Simple Single Sign On