CVE advisoryCRITICAL
CVE-2025-9485
WordPress OAuth SSO Plugin Vulnerability Allows Account Takeover
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A vulnerability in a WordPress OAuth SSO plugin allows unauthenticated attackers to bypass authentication due to unsafe token processing. This could lead to unauthorized access to any user account, including administrators, or the creation of new accounts.