CVE-2023-1093
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
- Affected products
- Oauth Single Sign On
- Miniorange Oauth Single Sign On
- < 6.24.2
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (25th percentile)
- NVD status
- Modified
- Published
- 2023-03-27
CVE-2023-1093 at NVD
1 known exploit for CVE-2023-1093
Proof-of-concept code and exploit modules indexed by Sploitus