WordPress Plugin Vulnerabilities

WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug Log File

Description

The plugin does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-27 (about 8 hours ago)

Other