Back to overview

CVE-2025-9485

CRITICAL
9.8
CVSS 3.1
Description
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts.

Metadata

CVE ID
CVE-2025-9485
State
PUBLISHED
Assigner
Wordfence
Reserved
2025-08-26 08:59 UTC
Published
2025-10-04 02:24 UTC
Last updated
2026-04-08 17:25 UTC
Primary CWE
CWE-347
CWE-347 Improper Verification of Cryptographic Signature
Vendor / Product
cyberlord92 / OAuth Single Sign On – SSO (OAuth Client)
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
cyberlord92 OAuth Single Sign On – SSO (OAuth Client) 0 ≤ 6.26.12
Weakness (CWE)
CWESourceDescription
CWE-347 cna CWE-347 Improper Verification of Cryptographic Signature
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview