What the vulnerability does
01Description
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The WP OAuth2 Server plugin for WordPress versions up to 1.0.1 contains a flaw that allows an attacker to read sensitive information without authentication. The vulnerability requires specific conditions to exploit but does not require user interaction. Site administrators should update the plugin to a version newer than 1.0.1 to protect user data.
What an attacker can do
Read sensitive information from the site without logging in.
Potential impact on your site
User data or OAuth tokens may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; specific conditions must be met to trigger the vulnerability.
Key dates
External resources