Input validation vulnerability in WP OAuth Server (OAuth Authentication) 4.2.5

The WP OAuth Server plugin for WordPress has an issue in versions up to, and including, 4.2.5. This issue is due to a lack of protection when it comes to validating certain AJAX actions (like wo_ajax_remove_self_generated_token). Without this protection, an unauthenticated attacker could cause a user to unknowingly click on a link and have their generated tokens removed.

Detected in:

WP OAuth Server (OAuth Authentication) open vulnerable versions: >= * <= 4.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.