What the vulnerability does
01Description
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Explanation of Vulnerability in Simple Terms
02Summary
The OAuth Single Sign On plugin for miniOrange contains an authentication flaw that allows an attacker with low-level site access to gain full control over the site, including reading sensitive data and modifying content. The vulnerability stems from improper validation of user credentials during the OAuth authentication flow. An attacker can bypass normal permission checks to escalate their privileges without additional user interaction.
What an attacker can do
03Attacker Capabilities
Read all site data, modify or delete content, and create new admin accounts.
Potential impact on your site
04Site Impact
Complete compromise of the site; attacker gains admin-level access and can steal user data or deface the site.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (subscriber, contributor, or similar).
Key dates
06Disclosure timeline
July 18, 2023
CVE published
April 28, 2026
Record updated