ZeroHour

CVE-2026-82183

moderate

Unauthenticated login bypass via Steam SSO in WordPress OAuth Single Sign On plugin

CVSS 3.1
8.1 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-82183 is an improper-authentication flaw (CWE-287) in the OAuth Single Sign On WordPress plugin: versions before 7.0.1 do not verify the identity assertion returned by the plugin's Steam single sign-on flow. An unauthenticated attacker who can reach that flow can submit an unverified identity assertion and be logged in as an arbitrary non-administrator user, and can also create new accounts on the site. Administrator accounts cannot be impersonated this way, which limits impact, but forged non-admin sessions and attacker-created accounts still enable content tampering and follow-on abuse. Any WordPress site running the plugin before 7.0.1 with the Steam SSO flow exposed is affected. No public proof-of-concept or in-the-wild exploitation is currently known (EPSS 0.2%, not in CISA KEV).

What to do: Update to OAuth Single Sign On 7.0.1 or later. As an interim mitigation, disable the Steam single sign-on option (or the plugin's login endpoints) until patched. Check the users list for unexpected new accounts and review recent logins for non-admin users; if suspicious sessions are found, force password resets and invalidate active sessions — administrator accounts are not directly at risk of takeover via this flaw.

Affected
miniOrange OAuth Single Sign On (WordPress plugin)all versions before 7.0.1
Estimated exposure
moderate≈10,000+ sites run the plugin (wordpress.org reports 10,000+ active installs); the plausibly affected subset with the Steam SSO flow enabled is likely in the… — Based on public wordpress.org active-install counts for the miniOrange OAuth Single Sign On plugin (~10,000+ installs), reduced to the subset of sites whose configuration exposes the vulnerable Steam login flow; exact Steam-enabled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.

Ecosystems
WordPress
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.