---
id: CVE-2025-9485
title: >-
  The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is
  vulnerable to Improper Verification of Cryptographic Signature in versions up
  to, and including, 6.26.12
summary: >-
  The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is
  vulnerable to Improper Verification of Cryptographic Signature in versions up
  to, and including, 6.26.12. This is due to the plugin performing unsafe JWT
  token process…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
published: '2025-10-04'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9485'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/miniorange-login-with-eve-online-google-facebook/tags/6.26.12/class-mooauth-widget.php#L577
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3360768/miniorange-login-with-eve-online-google-facebook
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/d2448afc-70d1-4dd5-b73b-62d182ee9a8a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00599
epssPercentile: 0.46997
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/jFriedli/CVE-2025-9485'
  checkedAt: '2026-10-08T22:12:30.007Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.782Z'
---

## Overview

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token` function. This makes it possible for unauthenticated attackers to bypass authentication and gain access to any existing user account - including administrators in certain configurations - or to create arbitrary subscriber-level accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
