Authentication Bypass Vulnerability Affects WordPress Sites Using OAuth Client Plugin
CVE-2024-10111
8.1HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 12 December 2024
What is CVE-2024-10111?
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to an authentication bypass due to inadequate verification of the user returning from a social login token. This vulnerability affects all versions up to and including 6.26.3. Consequently, unauthenticated attackers can gain unauthorized access, logging in as any existing user on the platform, which potentially includes roles with administrative privileges. The flaw arises when the plugin does not properly validate users who authenticate through various social platforms, allowing access to accounts even if the attacker does not possess legitimate authentication credentials.
Affected Version(s)
OAuth Single Sign On – SSO (OAuth Client) * <= 6.26.3