---
id: CVE-2026-82843
title: >-
  The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0
  does not bind the OpenID Connect identity assertion it issues to the
  authorization grant being exchanged, returning instead the assertion belonging
  to whichever u…
summary: >-
  The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0
  does not bind the OpenID Connect identity assertion it issues to the
  authorization grant being exchanged, returning instead the assertion belonging
  to whichever u…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-287
product: WP OAuth Server ( Login with WordPress )
affected:
  - wp_oauth_server_login_with_wordpress < 6.4.0
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:43:01.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82843'
references:
  - url: 'https://wpscan.com/vulnerability/45bc7096-5d04-4fe6-a332-31aed507a3a0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00187
epssPercentile: 0.07365
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T10:47:10.118793Z'
ingestedAt: '2026-09-23T06:17:57.887Z'
---

## Overview

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
