CVE-2022-34155 HIGH

CVE-2022-34155: WordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken Authentication

Vendor Miniorange
Product OAuth Single Sign On – SSO (OAuth Client)
Weakness CWE-287 · Improper authentication
Published July 18, 2023
Last update April 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

Explanation of Vulnerability in Simple Terms

02Summary

The OAuth Single Sign On plugin for miniOrange contains an authentication flaw that allows an attacker with low-level site access to gain full control over the site, including reading sensitive data and modifying content. The vulnerability stems from improper validation of user credentials during the OAuth authentication flow. An attacker can bypass normal permission checks to escalate their privileges without additional user interaction.

What an attacker can do

03Attacker Capabilities

Read all site data, modify or delete content, and create new admin accounts.

Potential impact on your site

04Site Impact

Complete compromise of the site; attacker gains admin-level access and can steal user data or deface the site.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the site (subscriber, contributor, or similar).

Key dates

06Disclosure timeline

July 18, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE