Back

MEDIUM

WP OAuth Server < 4.3.0 - Subscriber+ Arbitrary Client Deletion

Published Mar 20, 2023

Description

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Mar 20, 2023
Updated Feb 26, 2025
Reserved Nov 28, 2022
CISA Vulnrichment
Updated Feb 26, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a