CVE-2026-92965
Received Received - Intake

Authentication Bypass in TikTok WordPress Plugin

Vulnerability report for CVE-2026-92965, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: WPScan

Description

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every request to the site rather than only on the administrator's sign-in.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tik_tok wordpress_plugin to 1.4.2 (exc)
tik_tok wordpress_plugin From 1.2.0 (inc) to 1.4.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The TikTok WordPress plugin before version 1.4.2 has a flaw where it does not verify if a request is authorized before redeeming an OAuth sign-in code from the URL. This allows any visitor to use the site's credentials to redeem their own OAuth code against TikTok's advertising platform. The plugin also matches codes loosely, so similar URLs can trigger the issue, and the callback runs on every site request instead of just during administrator sign-ins.

Detection Guidance

Check if the TikTok WordPress plugin version is between 1.2.0 and 1.4.1. Inspect server logs for unusual OAuth callback requests or unauthorized access attempts to the advertising platform. Look for signs of code redemption activity outside administrator sign-ins.

Impact Analysis

This vulnerability could allow unauthorized users to access the site's TikTok advertising account by redeeming their own OAuth codes. It may lead to misuse of the site's credentials, potential data breaches, or unauthorized actions on the advertising platform. The impact is limited by a low CVSS score of 3.7, but it still poses a security risk.

Mitigation Strategies

Update the TikTok WordPress plugin to version 1.4.2 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review and restrict access to OAuth-related endpoints on your WordPress site.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92965. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart