Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in a WordPress plugin for Single Sign-On (SSO) could allow unauthenticated attackers to bypass authentication and access user accounts or create new ones. This issue stems from the plugin’s improper handling of security tokens, which might allow unauthorized access depending on the system's configuration.
- Unsafe token processing can bypass login.
- Critical authentication flaw affects user access.
- Confirm if this plugin is in use.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can initiate a request to the WordPress site, leveraging the plugin's improper handling of JWT tokens. By crafting a malicious token, the attacker can bypass authentication, potentially gaining access to any user account or creating new administrator accounts.
- No login required to attack.
- Unsafe token processing triggers vulnerability.
- Full account access or creation.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated attacker could bypass authentication for the WordPress site, gaining access to any user account, including administrator accounts, or creating new subscriber accounts. This is possible when the OAuth Single Sign-On plugin improperly processes JWT tokens without verification.
- User accounts could be accessed.
- Unauthenticated access to sensitive functions.
- Unauthorized account creation or takeover.
Operational Fix
Recommended remediation, mitigation, and detection steps
To address this critical vulnerability, WordPress site administrators and potentially their infrastructure or platform teams are responsible for managing the affected plugin. The first practical step is to identify all WordPress installations using the OAuth Single Sign-On plugin, determine if these sites are publicly accessible, and then confirm the accountable owner for each instance to plan remediation.
- Identify site owners and public-facing instances.
- Verify plugin presence and public accessibility.
- Plan controlled updates or mitigation.