CVE-2025-10753
Unknown Unknown - Not Provided
Unauthorized Access in WordPress OAuth SSO via Redirect URL

Publication date: 2026-02-06

Last updated on: 2026-02-06

Assigner: Wordfence

Description
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' option parameter. This makes it possible for unauthenticated attackers to set the global redirect URL option via the redirect_url parameter granted they can access the site directly.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-06
Last Modified
2026-02-06
Generated
2026-06-16
AI Q&A
2026-02-06
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
miniorange oauth_single_sign_on to 6.26.14 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress has a vulnerability in all versions up to and including 6.26.14. This vulnerability arises because the plugin does not properly check user capabilities or verify authentication when handling the OAuth redirect functionality via the 'oauthredirect' option parameter.

As a result, unauthenticated attackers who can directly access the site can exploit this flaw to set the global redirect URL option by manipulating the redirect_url parameter.

Impact Analysis

This vulnerability allows unauthenticated attackers to change the global redirect URL used by the OAuth Single Sign On plugin. This could lead to unauthorized redirection of users to malicious sites.

While the vulnerability does not directly impact confidentiality or availability, it can impact the integrity of the authentication flow by enabling attackers to redirect users without proper authorization.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

The vulnerability affects all versions of the OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress up to and including 6.26.14.

To mitigate this vulnerability, you should immediately update the plugin to a version later than 6.26.14, as the vulnerability is fixed in versions after this.

Since the vulnerability allows unauthenticated attackers to set the global redirect URL via the redirect_url parameter, restricting direct access to the vulnerable OAuth redirect functionality or disabling the plugin until an update can be applied may also help reduce risk.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-10753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart