
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10753 is a Missing Authorization vulnerability in the OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress, developed by cyberlord92/miniOrange. All versions up to and including 6.26.14 are affected. The flaw allows unauthenticated attackers to modify the global OAuth redirect URL by exploiting missing capability checks and authentication verification on the oauthredirect option parameter. It was published on February 6, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). The plugin's OAuth redirect functionality, accessible via the oauthredirect option parameter, performs no capability checks or authentication verification before processing the redirect_url parameter. Any unauthenticated network attacker who can reach the WordPress site can send a crafted HTTP request to set the global OAuth redirect URL to an arbitrary destination. The vulnerable code path is visible in the plugin's class-mooauth-widget.php file (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to redirect all OAuth SSO login flows to an attacker-controlled URL, enabling credential harvesting and session hijacking against any user who attempts to log in via the SSO plugin. The integrity impact is limited to modification of the redirect URL setting, with no direct confidentiality or availability impact on the server itself; however, the downstream risk to end users is significant as credentials submitted to a phishing site can lead to full account compromise. Lateral movement within the WordPress environment or broader infrastructure is possible if harvested credentials belong to administrators (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.128%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication, no user interaction, and low attack complexity, making it trivially easy to attempt against any exposed WordPress site running the affected plugin (Wordfence).
readme.txt at /wp-content/plugins/miniorange-login-with-eve-online-google-facebook/readme.txt or using tools like WPScan.oauthredirect option parameter and a redirect_url value pointing to an attacker-controlled phishing site (e.g., https://target.com/?oauthredirect=1&redirect_url=https://attacker.com/phish).oauthredirect and redirect_url parameters originating from unknown or suspicious IP addresses.oauthredirect=1 and an external redirect_url value; repeated attempts from the same IP may indicate scanning activity.wp_options table entry for the plugin's redirect URL option changed to an external or unfamiliar domain.Update the OAuth Single Sign On – SSO (OAuth Client) plugin to version 6.26.15 or later, which introduces proper capability checks and authentication verification on the OAuth redirect functionality. No configuration-based workaround is available for unpatched versions; site administrators unable to update immediately should consider temporarily disabling the plugin. The patch is available via the WordPress plugin repository (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for February 2–8, 2026, noting the availability of a patch in version 6.26.15 (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."