OpenID Connect Vulnerability in WP OAuth Server Plugin for WordPress
CVE-2026-82843
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-82843?
The WP OAuth Server plugin for WordPress prior to version 6.4.0 contains a vulnerability that improperly binds the OpenID Connect identity assertion to its corresponding authorization grant. When this flaw is exploited, it allows users with a Subscriber role and higher to receive a signed identity assertion belonging to another user who authenticated most recently. This issue potentially gives an attacker the ability to impersonate any user, including administrators, across applications that utilize the site's single sign-on feature.
Affected Version(s)
WP OAuth Server ( Login with WordPress ) 0 < 6.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.