External risk intelligence

WordPress OAuth SSO Plugin Vulnerability Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-9485

This vulnerability exists in an OAuth Single Sign-On plugin for WordPress. OAuth and SSO solutions are by design public-facing services meant to handle user authentication requests from the internet. As a critical component of the login flow for a web application, it is exposed to the public internet in any standard deployment where external authentication is enabled.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in a WordPress plugin for Single Sign-On (SSO) could allow unauthenticated attackers to bypass authentication and access user accounts or create new ones. This issue stems from the plugin’s improper handling of security tokens, which might allow unauthorized access depending on the system's configuration.

  • Unsafe token processing can bypass login.
  • Critical authentication flaw affects user access.
  • Confirm if this plugin is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can initiate a request to the WordPress site, leveraging the plugin's improper handling of JWT tokens. By crafting a malicious token, the attacker can bypass authentication, potentially gaining access to any user account or creating new administrator accounts.

  • No login required to attack.
  • Unsafe token processing triggers vulnerability.
  • Full account access or creation.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could bypass authentication for the WordPress site, gaining access to any user account, including administrator accounts, or creating new subscriber accounts. This is possible when the OAuth Single Sign-On plugin improperly processes JWT tokens without verification.

  • User accounts could be accessed.
  • Unauthenticated access to sensitive functions.
  • Unauthorized account creation or takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, WordPress site administrators and potentially their infrastructure or platform teams are responsible for managing the affected plugin. The first practical step is to identify all WordPress installations using the OAuth Single Sign-On plugin, determine if these sites are publicly accessible, and then confirm the accountable owner for each instance to plan remediation.

  • Identify site owners and public-facing instances.
  • Verify plugin presence and public accessibility.
  • Plan controlled updates or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the OAuth Single Sign-On plugin for WordPress?

This software component enables WordPress sites to integrate with external identity providers. It allows users to log in to their WordPress accounts using credentials from services like Google or Facebook, streamlining the authentication process by managing the exchange of tokens between the site and the identity provider.

How does CWE-347 apply to CVE-2025-9485?

CWE-347 refers to improper verification of cryptographic signatures. In this CVE, the plugin fails to check the integrity and authenticity of JSON Web Tokens (JWTs). Because the software does not verify these signatures, an attacker can submit a forged token that the system falsely accepts as legitimate, bypassing the entire login process.

When does this vulnerability trigger?

The issue is triggered when the plugin processes a manipulated identity token. It does not require an attacker to have a pre-existing account or administrative privileges to exploit. Conversely, the bug is not triggered if the OAuth functionality is completely disabled or if the plugin is not active on the WordPress instance.

Do I need to worry about this if my site is internal?

Halo Surface Signal indicates this plugin is designed to be public-facing, as it handles authentication requests from the internet. Even if your site is intended for internal use, if the login page is reachable via the web, it is considered exposed. You should prioritize assessing this risk regardless of the site's intended user base.

How do I respond to CVE-2025-9485?

Start by auditing your WordPress environment to confirm if this specific OAuth SSO plugin is installed and active. Once identified, document which instances are accessible to the public. Coordinate with your site administrators to restrict access or apply updates as provided by the plugin vendor to remediate the flaw.

References