6.5
CVSSv3

CVE-2023-1092

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00132 | KEV: Not Included
Published: 27/03/2023 Updated: 19/02/2025

Vulnerability Summary

The OAuth Single Sign On Free WordPress plugin prior to 6.24.2, OAuth Single Sign On Standard WordPress plugin prior to 28.4.9, OAuth Single Sign On Premium WordPress plugin prior to 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin prior to 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow malicious users to make logged in admins delete arbitrary IdP via a CSRF attack

Vulnerable Product Search on Vulmon Subscribe to Product

miniorange oauth single sign on free

miniorange oauth single sign on standard

miniorange oauth single sign on premium

miniorange oauth single sign on enterprise

miniorange oauth single sign on