Beveiligingsadvies

CVE-2023-1093

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-03-27 15:37:22
Laatst bijgewerkt 2025-02-19 20:16:48
Toegewezen door WPScan
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack