CVE-2026-82183 PUBLISHED

OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion

Assigner: WPScan
Reserved: 28.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.

Product Status

Vendor Unknown
Product OAuth Single Sign On
Versions Default: unaffected
  • affected from 6.25.0 to 7.0.1 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE