Cross-Site Request Forgery Vulnerability in OAuth Client Plugin for WordPress
CVE-2025-10752
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 September 2025
What is CVE-2025-10752?
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress contains a vulnerability that allows Cross-Site Request Forgery (CSRF) attacks. The issue arises from the implementation of a predictable state parameter (base64 encoded app name) during the OAuth flow without sufficient randomness. This flaw enables unauthenticated attackers to create forged OAuth authorization requests. If a site administrator is tricked into performing an action, such as clicking on a malicious link, the attacker could hijack the OAuth flow, potentially compromising sensitive user data and permissions.
Affected Version(s)
OAuth Single Sign On – SSO (OAuth Client) * <= 6.26.12