CVE Database
/

CVE-2022-4148

Back to search

CVE-2022-4148

Published: Mar 20, 2023

Modified: Feb 26, 2025

PUBLISHED

Description

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

VendorProductVersions

Unknown

WP OAuth Server (OAuth Authentication)

affected
0 - < 4.3.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now