← WordPress Vulnerabilities
WordPress security by component

OAuth Single Sign On – SSO (OAuth Client)

OAuth Single Sign On – SSO (OAuth Client) is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Feb 06, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: miniorange-login-with-eve-online-google-facebook

CVE-2025-10753: OAuth Single Sign On – SSO (OAuth Client): A security weakness

OAuth Single Sign On – SSO (OAuth Client) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedFeb 06, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 06, 2026 CVE-2025-10753
OAuth Single Sign On – SSO (OAuth Client): A security weakness
OAuth Single Sign On – SSO (OAuth Client) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Oct 04, 2025 CVE-2025-9485
OAuth Single Sign On – SSO (OAuth Client): A security weakness
OAuth Single Sign On – SSO (OAuth Client) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Sep 26, 2025 CVE-2025-10752
OAuth Single Sign On – SSO (OAuth Client): Cross-site request forgery
OAuth Single Sign On – SSO (OAuth Client) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 12, 2024 CVE-2024-10111
OAuth Single Sign On – SSO (OAuth Client): Privilege escalation or authentication bypass
OAuth Single Sign On – SSO (OAuth Client) is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Jul 18, 2023 CVE-2022-34155
OAuth Single Sign On – SSO (OAuth Client): Privilege escalation or authentication bypass
OAuth Single Sign On – SSO (OAuth Client) is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8