← WordPress Vulnerabilities
WordPress security by component

OAuth Single Sign On

OAuth Single Sign On enables WordPress users to sign in through supported OAuth identity providers.

OAuth Single Sign On (oauth-single-sign-on) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 8.1.

Plugin slug: oauth-single-sign-on

CVE-2026-82183: OAuth Single Sign On permits arbitrary non-administrator login through Steam SSO

OAuth Single Sign On 6.25.0 through 7.0.0 does not verify the identity assertion returned by its Steam single-sign-on flow. An unauthenticated attacker can log in as an arbitrary non-administrator user or create a new account.

PublishedSep 02, 2026
Known safe version7.0.1
Published vulnerabilities for oauth-single-sign-on
Safe version
Sep 02, 2026 CVE-2026-82183
OAuth Single Sign On permits arbitrary non-administrator login through Steam SSO
OAuth Single Sign On 6.25.0 through 7.0.0 does not verify the identity assertion returned by its Steam single-sign-on flow. An unauthenticated attacker can log in as an arbitrary non-administrator user or create a new account.
7.0.1
CVE8.1
NVDPending
Mar 27, 2023 CVE-2023-1093
OAuth Single Sign On: Cross-site request forgery
OAuth Single Sign On is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Mar 27, 2023 CVE-2023-1092
OAuth Single Sign On Free: Cross-site request forgery
OAuth Single Sign On Free is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Jul 17, 2022 CVE-2022-2133
OAuth Single Sign On: A security weakness
OAuth Single Sign On is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3