Authentication vulnerability in OAuth 2.0 client for SSO 1.11.3

The OAuth 2.0 Client for SSO plugin for WordPress has a security issue. Unauthenticated attackers can use someone else’s email address to log in as a site administrator without needing a password. This issue affects versions up to 1.11.3 of the plugin and is caused by the plugin accepting the user supplied email address without verifying if it belongs to the person who is trying to log in.

Detected in:

OAuth 2.0 client for SSO open vulnerable versions: >= * <= 1.11.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.