cbcvebase.
CVE-2023-1092
published 2023-03-27

CVE-2023-1092: The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium…

PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.44%
37.7th percentile
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

Affected

8 ranges
VendorProductVersion rangeFixed in
miniorangeoauth_single_sign_on< 6.24.26.24.2
miniorangeoauth_single_sign_on< 28.4.928.4.9
miniorangeoauth_single_sign_on< 38.4.938.4.9
miniorangeoauth_single_sign_on< 48.4.948.4.9
miniorangeoauth_single_sign_on_enterprise< 48.4.948.4.9
miniorangeoauth_single_sign_on_free< 6.24.26.24.2
miniorangeoauth_single_sign_on_premium< 38.4.938.4.9
miniorangeoauth_single_sign_on_standard< 28.4.928.4.9
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.