CRITICAL
WordPress WP OAuth Server plugin <= 3.0.4 - Authentication Bypass vulnerability
Published Aug 22, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.28%
Description
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
Affected products
-
Affected
- ≤ 3.0.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| miniOrange | WP OAuth Server (WordPress plugin) | unaffected | Affected
|
- ≤ 3.0.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 4.0.1 or a higher version.
Weaknesses (2)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37164 Advisory
- https://lana.codes/lanavdb/6d794d65-d44b-4099-94c5-3dd2995b218c?_s_id=cve third-party-advisory
- https://patchstack.com/database/vulnerability/miniorange-oauth-20-server/wordpress-wp-oauth-server-plugin-3-0-4-authentication-bypass-vulnerability?_s_id=cve vdb-entry
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Aug 22, 2022
Updated Apr 28, 2026
Reserved Jun 30, 2022
Link CVE-2022-34149
CISA Vulnrichment
Updated Feb 20, 2025
Red Hat
No data
GitHub
No data