WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in OAuth Single Sign On – SSO (OAuth Client)

WordPress SSO (Single Sign On) with Azure, Okta, Cognito, Keycloak, OAuth & OpenID Providers. Free Unlimited SSO Authentication [24/7 Support]

8Reported vulnerabilities
9.8Highest CVSS score
7.1.0Latest version
6,000+Active installs

What to do now

Update OAuth Single Sign On – SSO (OAuth Client) to 6.26.15 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 13, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-1092 Medium 6.5 0.4% 0 up to (but not including) 6.24.2
0 up to (but not including) 28.4.9
0 up to (but not including) 38.4.9
0 up to (but not including) 48.4.9
6.24.2 March 27, 2023
CVE-2025-9485 Critical 9.8 0.6% 0 to 6.26.12 (inclusive) 6.26.13 October 4, 2025
CVE-2022-34155 High 8.8 1.0% 6.23.3 and earlier 6.23.4 May 24, 2023
CVE-2024-10111 High 8.1 0.8% 0 to 6.26.3 (inclusive) 6.26.4 December 12, 2024
WF-bb2a67ff-a452-4ecb-9fd7-bf05fe43a2f7 Medium 6.4 6.22.5 and earlier 6.23.0 June 22, 2022
WF-44cbaa25-7e91-4b2e-81c4-ba1d7ba02350 Medium 6.1 6.20.2 and earlier 6.20.3 August 30, 2021
CVE-2025-10753 Medium 5.3 0.3% 0 to 6.26.14 (inclusive) 6.26.15 February 6, 2026
CVE-2025-10752 Medium 4.3 0.2% 0 to 6.26.12 (inclusive) 6.26.13 September 26, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.