Dash10's vulnerability profile centers on its OAuth server product, which handles authentication and authorization across client applications and must defend against cross-origin and cryptographic threats. The durable signal across its disclosures reflects weaknesses in request validation, authorization enforcement, and random-number generation—issues characteristic of identity and access-control infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dash10 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9435CRITICAL The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | Sep 26, 2019 | 9.8 | 24 | NO | NO |
CVE-2022-4148MEDIUM The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users | Mar 20, 2023 | 4.3 | 18 | NO | NO |
CVE-2022-3894MEDIUM The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actua | Mar 20, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dash10.
Media articles that mention a CVE ID that affects a product developed by Dash10 — matched by CVE ID, not by vendor name.