WordPress Plugin Vulnerabilities

OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion

Description

The plugin does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 22 days ago)
Added
2026-08-31 (about 22 days ago)
Last Updated
2026-09-21 (about 19 hours ago)

Other