CyberRota Analysis
AI-GeneratedThe OAuth Single Sign On plugin for WordPress versions prior to 7.0.1 is vulnerable due to a lack of verification for identity assertions in its Steam single sign-on flow. This flaw allows unauthenticated attackers to log in as any non-administrator user and create new accounts, potentially compromising site integrity and user data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.
Original NVD Description
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.