SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19715

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The WP OAuth Server plugin for WordPress prior to version 6.3.1 is vulnerable due to improper access controls on its debug log, which is publicly accessible. This flaw allows unauthenticated users to read sensitive information, including OAuth tokens, authorization codes, and user records with password hashes if debug logging is enabled. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.

CVE
CVE-2026-19715
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.