Simple Single Sign On <= 4.1.0 - Authentication Bypass
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.
Affected products
Unknown · Simple Single Sign On