CVE-2023-1092

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:standard:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:premium:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:enterprise:wordpress:*:*

History

07 Nov 2023, 04:02

Type Values Removed Values Added
CWE CWE-352

Information

Published : 2023-03-27 16:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-1092

Mitre link : CVE-2023-1092

CVE.ORG link : CVE-2023-1092


JSON object : View

Products Affected

miniorange

  • oauth_single_sign_on
CWE

No CWE.