Description
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) is prone to multiple cross-site request forgery vulnerabilities. Exploiting these issues may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) version 6.24.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.24.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:8FBF7EFE-0BF2-42C6-AEF1-7FCF2708B31B
https://sploitus.com/exploit?id=WPEX-ID:1E13B9EA-A3EF-483B-B967-6EC14BD6D54D
https://plugins.svn.wordpress.org/miniorange-login-with-eve-online-google-facebook/trunk/readme.txt
Related Vulnerabilities
MySQL CVE-2021-2180 Vulnerability (CVE-2021-2180)
WordPress Plugin Donorbox-Free Recurring Donation Form Cross-Site Scripting (7.1.1)
e107 Other Vulnerability (CVE-2004-2039)
WordPress Plugin HTML5 jQuery Audio Player Multiple Cross-Site Scripting Vulnerabilities (2.3)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.5)