Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9485

Опубликовано: 04 окт. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the get_resource_owner_from_id_token function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts.

EPSS

Процентиль: 68%
0.0056
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts.

EPSS

Процентиль: 68%
0.0056
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347