CVE-2026-82183
Received Received - Intake

OAuth Bypass in WordPress Steam SSO Plugin

Vulnerability report for CVE-2026-82183, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oauth_single_sign_on plugin From 6.25.0 (inc) to 7.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The OAuth Single Sign On WordPress plugin before version 7.0.1 has a flaw in its Steam single sign-on flow where it does not verify the identity assertion returned by Steam. This allows unauthenticated attackers to log in as any non-administrator user or create new accounts without authentication.

Detection Guidance

Check the installed version of the OAuth Single Sign On WordPress plugin. If it is between 6.25.0 and 7.0.0, the system is vulnerable. Logs may show unauthorized login attempts or new account creations without prior authentication.

Impact Analysis

Attackers can exploit this to gain unauthorized access to user accounts or create new accounts, potentially leading to data breaches, unauthorized actions, or further compromise of the WordPress site. The vulnerability is classified as an authentication bypass with high severity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating compliance requirements under GDPR, HIPAA, or other regulations that mandate strict access controls and authentication mechanisms.

Mitigation Strategies

Update the OAuth Single Sign On plugin to version 7.0.1 or later immediately. Disable the Steam single sign-on flow temporarily if an update is not possible. Monitor for suspicious account activity or unauthorized logins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82183. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart