Known vulnerabilities in OAuth Single Sign On – SSO (OAuth Client)
WordPress SSO (Single Sign On) with Azure, Okta, Cognito, Keycloak, OAuth & OpenID Providers. Free Unlimited SSO Authentication [24/7 Support]
8Reported vulnerabilities
9.8Highest CVSS score
7.1.0Latest version
6,000+Active installs
What to do now
Update OAuth Single Sign On – SSO (OAuth Client) to 6.26.15 or later.
8 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2023-1092 | Medium | 0.4% | 0 up to (but not including) 6.24.2 0 up to (but not including) 28.4.9 0 up to (but not including) 38.4.9 0 up to (but not including) 48.4.9 |
6.24.2 |
March 27, 2023 |
| CVE-2025-9485 | Critical | 0.6% | 0 to 6.26.12 (inclusive) | 6.26.13 |
October 4, 2025 |
| CVE-2022-34155 | High | 1.0% | 6.23.3 and earlier | 6.23.4 |
May 24, 2023 |
| CVE-2024-10111 | High | 0.8% | 0 to 6.26.3 (inclusive) | 6.26.4 |
December 12, 2024 |
| WF-bb2a67ff-a452-4ecb-9fd7-bf05fe43a2f7 | Medium | — | 6.22.5 and earlier | 6.23.0 |
June 22, 2022 |
| WF-44cbaa25-7e91-4b2e-81c4-ba1d7ba02350 | Medium | — | 6.20.2 and earlier | 6.20.3 |
August 30, 2021 |
| CVE-2025-10753 | Medium | 0.3% | 0 to 6.26.14 (inclusive) | 6.26.15 |
February 6, 2026 |
| CVE-2025-10752 | Medium | 0.2% | 0 to 6.26.12 (inclusive) | 6.26.13 |
September 26, 2025 |