CVE-2026-82183
moderateUnauthenticated login bypass via Steam SSO in WordPress OAuth Single Sign On plugin
CVE-2026-82183 is an improper-authentication flaw (CWE-287) in the OAuth Single Sign On WordPress plugin: versions before 7.0.1 do not verify the identity assertion returned by the plugin's Steam single sign-on flow. An unauthenticated attacker who can reach that flow can submit an unverified identity assertion and be logged in as an arbitrary non-administrator user, and can also create new accounts on the site. Administrator accounts cannot be impersonated this way, which limits impact, but forged non-admin sessions and attacker-created accounts still enable content tampering and follow-on abuse. Any WordPress site running the plugin before 7.0.1 with the Steam SSO flow exposed is affected. No public proof-of-concept or in-the-wild exploitation is currently known (EPSS 0.2%, not in CISA KEV).
What to do: Update to OAuth Single Sign On 7.0.1 or later. As an interim mitigation, disable the Steam single sign-on option (or the plugin's login endpoints) until patched. Check the users list for unexpected new accounts and review recent logins for non-admin users; if suspicious sessions are found, force password resets and invalidate active sessions — administrator accounts are not directly at risk of takeover via this flaw.
| miniOrange OAuth Single Sign On (WordPress plugin) | all versions before 7.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
- Ecosystems
- WordPress
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.