PT-2022-14844 · WordPress · The Simple Single Sign On

Lana Codes

+1

·

Published

2022-09-05

·

Updated

2023-08-02

·

CVE-2022-2083

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Simple Single Sign On WordPress plugin versions through 4.1.0
Description The issue allows attackers to gain unauthorized access to the site by leaking its OAuth client secret. This could potentially lead to malicious activities.
Recommendations For The Simple Single Sign On WordPress plugin versions through 4.1.0, update to a version later than 4.1.0 to prevent the leak of the OAuth client secret. As a temporary workaround, consider restricting access to the OAuth functionality until a patch is available.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-2083

Affected Products

The Simple Single Sign On