Miniorange
Miniorange Oauth Single Sign ON: vulnerabilidades y CVE
Miniorange Oauth Single Sign ON tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82183 | Alta (8.1) | 0.38% | — | 2 sept 2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator… |
| CVE-2025-10753 | Media (5.3) | 0.38% | — | 6 feb 2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication… |
| CVE-2025-10752 | Media (4.3) | 0.17% | — | 26 sept 2025 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64… |
| CVE-2022-34155 | Alta (8.8) | 0.96% | — | 18 jul 2023 | Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3. |
| CVE-2023-1093 | Media (6.5) | 0.33% | — | 27 mar 2023 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack |
| CVE-2023-1092 | Media (6.5) | 0.44% | — | 27 mar 2023 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise… |
| CVE-2022-2133 | Media (5.3) | 1.2% | — | 17 jul 2022 | The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Miniorange
Miniorange 2FA · 12Google Authenticator · 7Active Directory Integration / Ldap Integration · 6Saml SP Single Sign ON · 5Malware Scanner · 5OTP Verification With Firebase · 4Wordpress Social Login AND Register · 4Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) · 3Discord Integration · 3Page Restriction · 2Custom API FOR WP · 2Password Policy Manager · 2