← WordPress Vulnerabilities
WordPress security by component

OAuth Server

OAuth Server is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 10, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: oauth2-provider

CVE-2024-31253: OAuth Server: An open redirect

OAuth Server is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.

PublishedApr 10, 2024
Safe version guidanceSee mitigation notes
Safe version
Apr 10, 2024 CVE-2024-31253
OAuth Server: An open redirect
OAuth Server is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
Sep 26, 2019 CVE-2015-9435
Oauth2 Provider: A security weakness
Oauth2 Provider is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8