CVE-2022-2133 OAuth plugin before 6.22.6 doesn't validate token requests, which allows attackers to log into site with user's email address.

CVE-2022-2133 OAuth plugin before 6.22.6 doesn't validate token requests, which allows attackers to log into site with user's email address.

This access token can then be used to request any type of resource on the website that the user has access to. This could be anything from adding new users to editing their profile information, changing their email address, and so on. The attacker cannot access any other data on the website, such as their user roles, their private messages, their settings, or their posts. This attack can be mitigated by making sure that your WordPress installation is not publicly accessible via a web server.

There are two ways to prevent this attack: 1) Use a self-hosted WordPress solution, or 2) Use a hosted WordPress solution that uses strict security protocols. The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

References

Subscribe to CVE.news
Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe