CVE-2023-1092

medium

Description

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

References

https://wpscan.com/vulnerability/f6e165d9-2193-4c76-ae2d-618a739fe4fb

https://wpscan.com/vulnerability/8fbf7efe-0bf2-42c6-aef1-7fcf2708b31b

https://wpscan.com/vulnerability/5eb85df5-8aab-4f30-a401-f776a310b09c

https://wpscan.com/vulnerability/52e29f16-b6dd-4132-9bb8-ad10bd3c39d7

Details

Source: Mitre, NVD

Published: 2023-03-27

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium