Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-02-19

CVE-2023-1093 - Oauth Single Sign On Plugin

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack

PLUGIN Oauth Single Sign On

CVE-2023-1093

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1092 - Oauth Single Sign On Plugin

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

PLUGIN Oauth Single Sign On

CVE-2023-1092

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2024-11-21

CVE-2022-2133 - Oauth Single Sign On Plugin

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

PLUGIN Oauth Single Sign On

CVE-2022-2133

MEDIUM CVSS 5.3 2022-07-17
Scroll to top