CVE-2026-82843
Last modified
CVE-2026-82843 is a critical-severity vulnerability rated 9/10 on the CVSS scale. The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | WP OAuth Server ( Login with WordPress ) | < 6.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-82843?
How severe is CVE-2026-82843?
How do I fix CVE-2026-82843?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82834A security flaw has been discovered in Doccano Open Source A…5.4
- CVE-2026-82835A weakness has been identified in caoqianming django-vue-adm…5.4
- CVE-2026-82837GitLab has remediated an issue in GitLab CE/EE affecting all…5.3
- CVE-2026-82838The default docker image shipped for Venueless did not prope…6.4
- CVE-2026-8284URL redirection to untrusted site ('open redirect') vulnerab…6.1
- CVE-2026-82842The SAML Single Sign On WordPress plugin before 6.0.0 does …8.1
- CVE-2026-82845The Masteriyo LMS WordPress plugin before 3.4.1 does not pr…9.9
- CVE-2026-82846The Masteriyo LMS WordPress plugin before 3.4.0 does not sa…6.8
- CVE-2026-82847The Masteriyo LMS WordPress plugin before 3.4.1 does not sa…6.8
- CVE-2026-82848The Masteriyo LMS WordPress plugin before 3.4.0 does not pe…5.3
- CVE-2026-82849The Masteriyo LMS WordPress plugin before 3.4.2 does not ve…4.3
- CVE-2026-8285Improper restriction of excessive authentication attempts vu…4.3
Are you affected by CVE-2026-82843?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
