CVE-2022-34858
WordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Una vulnerabilidad de elusión de autenticación en el cliente miniOrange Oauth versión 2.0 para el plugin SSO versiones anteriores a 1.11.3 incluyéndola, en WordPress.
The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3. This is due to the plugin accepting a user supplied email address that is passed to wp_set_auth_cookie() with no further identity validation to verify that the email supplied belongs to the user trying to log in with that email address. This makes it possible for unauthenticated attackers to log in as a site administrator granted they have access to a site admin's email address.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-23 CVE Published
- 2022-06-30 CVE Reserved
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
- CWE-306: Missing Authentication for Critical Function
CAPEC
- CAPEC-115: Authentication Bypass
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/oauth-client/wordpress-oauth-2-0-client-for-sso-plugin-1-11-3-authentication-bypass-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://lana.codes/lanavdb/df23b19f-4134-41d3-8cb3-9d44189b461b?_s_id=cve | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Miniorange Search vendor "Miniorange" | Oauth 2.0 Client For Sso Search vendor "Miniorange" for product "Oauth 2.0 Client For Sso" | < 1.11.4 Search vendor "Miniorange" for product "Oauth 2.0 Client For Sso" and version " < 1.11.4" | wordpress |
Affected
|