Skip to main content

Vendor/product archive

miniorange / oauth_single_sign_on CVEs

Beta · best-effort

4 CVEs tagged to miniorange / oauth_single_sign_on0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-34155

Published Jul 18, 2023

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OA…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1093

Published Mar 27, 2023

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins de…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1092

Published Mar 27, 2023

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2133

Published Jul 17, 2022

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1