CVE-2025-10753
OAuth Single Sign On – SSO (OAuth Client)
Minimum safe version
6.26.15
Update to 6.26.15 or later to address 13 fixable vulnerabilities
OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Cross-Site Request Forgery
OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token()
CVE-2024-10111
Multiple Plugins from miniorange - Reflected Cross-Site Scripting via appId
CVE-2022-34155
CVE-2023-1093
CVE-2023-1092
WordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
OAuth Single Sign On – SSO (OAuth Client) <= 6.24.1- Cross-Site Request Forgery via 'discard' in mooauth_client_applist_page
Multiple miniOrange Plugins (Various Version) - Reflected Cross-Site Scripting
OAuth Single Sign On – SSO (OAuth Client) <= 6.22.5 - Cross-Site Scripting
CVE-2022-2133