Unauthorized Access Vulnerability in Secufor_OAuth Plugin for WordPress
CVE-2026-7617
5.3MEDIUM
What is CVE-2026-7617?
The Secufor_OAuth plugin for WordPress suffers from a serious security flaw that allows unauthorized users to gain access to functionalities without proper authentication. In all versions up to and including 1.0.7, the plugin fails to adequately verify if a user is authorized to perform specific actions. This vulnerability enables unauthenticated attackers to disconnect a WordPress site from its linked Secufor account by removing the stored login token and user login settings, potentially leading to further security risks.
Affected Version(s)
Secufor_OAuth 0 <= 1.0.7