Input validation vulnerability in OAuth Single Sign On – SSO (OAuth Client) 6.24.1

The OAuth Single Sign On plugin for WordPress (also known as the OAuth Client) is not secure in versions up to 6.24.1. This means that someone who is not logged in can make changes to the settings of the plugin if they can get someone logged in (like an administrator) to click on a link they send them. This is because the plugin does not have the proper security measures to check that the person making the changes is really allowed to do so.

Detected in:

OAuth Single Sign On – SSO (OAuth Client) fixed vulnerable versions: >= * <= 6.24.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.