CVE Vulnerabilities

CVE-2023-1093

Published: Mar 27, 2023 | Modified: Feb 19, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack

Affected Software

NameVendorStart VersionEnd Version
Oauth_single_sign_onMiniorange*6.24.2 (excluding)

References