SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82183

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The OAuth Single Sign On plugin for WordPress versions prior to 7.0.1 is vulnerable due to a lack of verification for identity assertions in its Steam single sign-on flow. This flaw allows unauthenticated attackers to log in as any non-administrator user and create new accounts, potentially compromising site integrity and user data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-82183
Severity
HIGH
CVSS
8.1
EPSS
0.23%
WordPress

Original NVD Description

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.