External risk intelligence

OAuth SSO Plugin Unauthenticated Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-97274

This vulnerability affects an OAuth Single Sign-On (SSO) plugin, which by design acts as an identity and authentication portal. Such services are intended to be public-facing to facilitate user authentication from the internet, making this component a primary network edge surface.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability impacting OAuth Single Sign-On (SSO) plugins that handle authentication. The flaw allows unauthenticated access to bypass security controls, potentially exposing sensitive information and system functions. While direct exploitation details are not provided, the nature of SSO systems means any compromise could have significant downstream effects on user accounts and data.

  • Unauthenticated bypass in sign-on systems.
  • Affects critical authentication and identity portals.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by targeting the OAuth Single Sign-On (SSO) feature without needing any prior authentication. This could allow them to bypass security measures and gain unauthorized access.

  • Unauthenticated network access.
  • Triggering the OAuth client bypass.
  • Unauthorized access to data and systems.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to bypass authentication mechanisms in an OAuth Single Sign-On (SSO) plugin. When a service relies on this plugin for user authentication, an attacker might be able to gain unauthorized access to user accounts and the associated application data without needing valid credentials.

  • Unauthenticated access to user accounts.
  • Bypass authentication via network.
  • Unauthorized access to account data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated bypass vulnerability in the OAuth Single Sign-On (SSO) plugin likely impacts platform or application teams responsible for identity management and user authentication. The first practical step is to identify all instances of the affected plugin, assess their exposure (especially public-facing ones), confirm business criticality, and then engage the accountable owner to prioritize and plan remediation, potentially coordinating with the plugin vendor.

  • Platform or application teams own the issue.
  • Verify public-facing plugin instances.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the OAuth Single Sign-On (SSO) plugin?

This software is a WordPress plugin designed to simplify user logins by allowing accounts to authenticate through external identity providers like Google, Facebook, or other OAuth-compliant services. It acts as a bridge that handles the secure exchange of user credentials, ensuring that when someone logs in, the application correctly verifies their identity before granting access to the site's resources.

How does the CVE-2026-97274 vulnerability work?

This issue is classified under CWE-290, which refers to authentication bypass by spoofing. In the context of this CVE, it means the plugin fails to properly verify the identity tokens returned during the sign-on process. Because the check is flawed, an attacker can trick the system into believing they have successfully authenticated, effectively skipping the password or identity verification steps entirely.

What triggers the OAuth bypass in this plugin?

The vulnerability is triggered when an attacker sends a specially crafted request to the plugin's authentication endpoint. Importantly, the flaw does not require the attacker to have a valid user account or any prior credentials. Simply interacting with the public-facing OAuth login flow in a way that exploits the verification gap is sufficient to bypass the intended security controls.

Why is this SSO vulnerability considered a high-risk issue?

Halo Surface Signal notes that since this plugin serves as an identity portal, it is designed to be internet-facing to handle incoming user traffic. Because the component sits at the network edge to facilitate logins, the authentication bypass is directly accessible to anyone on the internet, significantly increasing the potential for unauthorized access to systems that rely on this plugin for user security.

Is my site affected by this OAuth plugin flaw?

If you are running the OAuth Single Sign-On (SSO) plugin version 7.1.2 or older, your installation is affected. You should start by creating an inventory of all sites using this specific plugin. Once identified, work with your team to review official updates from the plugin developer and prioritize applying the latest secure version to resolve the bypass vulnerability.

References