ZeroHour

CVE-2023-1093

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p26
Published
()
Modified
Description

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack

Vendors
miniorange
Products
oauth single sign on
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.