CVE-2025-10752 affects the OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress, specifically versions up to and including 6.26.12. This Cross-Site Request Forgery (CSRF) vulnerability stems from the use of a predictable, non-random state parameter in the OAuth flow. An unauthenticated attacker could exploit this by tricking a site administrator into clicking a malicious link, potentially hijacking the OAuth authorization process. The vulnerability is rated Medium severity (CVSS 4.3) due to its network attack vector and low attack complexity, though it requires user interaction and has a low impact on integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cyberlord92 | OAuth Single Sign On – SSO (OAuth Client) | >= 0, <= 6.26.12CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.