WP OAuth Server < 4.3.0 – Subscriber+ Arbitrary Client Deletion
Discription

The plugin has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

### PoC

The PoC will be displayed on March 07, 2023, to give users the time to update.Read More

Back to Main

Subscribe for the latest news: