« Volver al listado

CVE-2022-2083

Estado: ModificadaAlta (7.5)—

El plugin Simple Single Sign On de WordPress versiones hasta 4.1.0, filtra su client_secret de OAuth, que podría ser usado por atacantes para conseguir acceso no autorizado al sitio

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2083",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "Simple Single Sign On",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "4.1.0"
            }
          ],
          "collectionURL": "https://wordpress.org/plugins",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2022-09-05T13:15:08.167",
  "references": [
    {
      "url": "https://lana.codes/lanavdb/0bab7575-45fc-432d-945e-6100c35c574c/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/2bbfc855-6901-462f-8a93-120d7fb5d268",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://lana.codes/lanavdb/0bab7575-45fc-432d-945e-6100c35c574c/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wpscan.com/vulnerability/2bbfc855-6901-462f-8a93-120d7fb5d268",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site."
    },
    {
      "lang": "es",
      "value": "El plugin Simple Single Sign On de WordPress versiones hasta 4.1.0, filtra su client_secret de OAuth, que podría ser usado por atacantes para conseguir acceso no autorizado al sitio"
    }
  ],
  "lastModified": "2026-06-17T04:41:15.053",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:simple_sign_on_project:simple_sign_on:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68F13D8A-175D-486C-B8B2-69D088617920",
              "versionEndIncluding": "4.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}