CVE-2025-10753: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-10753 is a Missing Authorization vulnerability in the OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress, developed by cyberlord92/miniOrange. All versions up to and including 6.26.14 are affected. The flaw allows unauthenticated attackers to modify the global OAuth redirect URL by exploiting missing capability checks and authentication verification on the oauthredirect option parameter. It was published on February 6, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). The plugin's OAuth redirect functionality, accessible via the oauthredirect option parameter, performs no capability checks or authentication verification before processing the redirect_url parameter. Any unauthenticated network attacker who can reach the WordPress site can send a crafted HTTP request to set the global OAuth redirect URL to an arbitrary destination. The vulnerable code path is visible in the plugin's class-mooauth-widget.php file (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an unauthenticated attacker to redirect all OAuth SSO login flows to an attacker-controlled URL, enabling credential harvesting and session hijacking against any user who attempts to log in via the SSO plugin. The integrity impact is limited to modification of the redirect URL setting, with no direct confidentiality or availability impact on the server itself; however, the downstream risk to end users is significant as credentials submitted to a phishing site can lead to full account compromise. Lateral movement within the WordPress environment or broader infrastructure is possible if harvested credentials belong to administrators (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.128%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication, no user interaction, and low attack complexity, making it trivially easy to attempt against any exposed WordPress site running the affected plugin (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin (versions ≤ 6.26.14) via passive techniques such as checking readme.txt at /wp-content/plugins/miniorange-login-with-eve-online-google-facebook/readme.txt or using tools like WPScan.
  2. Craft malicious request: Prepare an HTTP GET or POST request targeting the plugin's OAuth redirect endpoint with the oauthredirect option parameter and a redirect_url value pointing to an attacker-controlled phishing site (e.g., https://target.com/?oauthredirect=1&redirect_url=https://attacker.com/phish).
  3. Submit request: Send the crafted request to the target site without any authentication headers or cookies. The plugin processes the request and updates the global redirect URL option in the WordPress database.
  4. Harvest credentials: Wait for legitimate users to initiate an OAuth SSO login. They will be redirected to the attacker's phishing page after authentication, where credentials or OAuth tokens can be captured.
  5. Exploit harvested credentials: Use captured credentials or tokens to access the victim's account on the WordPress site or connected OAuth provider (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected HTTP requests to the WordPress site containing oauthredirect and redirect_url parameters originating from unknown or suspicious IP addresses.
  • Logs: WordPress access logs showing unauthenticated requests to plugin endpoints with oauthredirect=1 and an external redirect_url value; repeated attempts from the same IP may indicate scanning activity.
  • Database: The WordPress wp_options table entry for the plugin's redirect URL option changed to an external or unfamiliar domain.
  • User Reports: End users reporting unexpected redirects to unfamiliar sites during the OAuth login flow.

Mitigation and workarounds

Update the OAuth Single Sign On – SSO (OAuth Client) plugin to version 6.26.15 or later, which introduces proper capability checks and authentication verification on the OAuth redirect functionality. No configuration-based workaround is available for unpatched versions; site administrators unable to update immediately should consider temporarily disabling the plugin. The patch is available via the WordPress plugin repository (Wordfence, WordPress Trac).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for February 2–8, 2026, noting the availability of a patch in version 6.26.15 (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management