CRITICAL 9.0 CVE-2026-82843 Published 23 Sept 2026

WP OAuth Server WordPress Plugin OpenID Connect Identity Assertion Flaw

Worried this affects your website?

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 contains an OpenID Connect identity assertion binding flaw. It does not bind the identity assertion it issues to the authorization grant being exchanged, instead returning the assertion belonging to whichever user authenticated most recently.

This allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.

  • Affected versions: before 6.4.0
  • Privilege required: Subscriber role or above
  • Impact: account takeover via single sign-on at relying applications

Reference: CVE-2026-82843 on NVD

← Back to Security News