PT-2025-39475 · WordPress · Wordpress Oauth Single Sign On

Published

2025-09-26

·

Updated

2025-09-26

·

CVE-2025-10752

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress OAuth Single Sign On plugin versions prior to 6.26.12
Description The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is susceptible to Cross-Site Request Forgery. This is a result of utilizing a predictable state parameter (base64 encoded app name) within the OAuth flow, lacking randomness. An unauthenticated attacker could potentially forge OAuth authorization requests and hijack the OAuth flow if they can trick a site administrator into performing an action, such as clicking a link.
Recommendations Update the WordPress OAuth Single Sign On plugin to version 6.26.12 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-10752

Affected Products

Wordpress Oauth Single Sign On