Wordpress Alert: OAuth account-linking flaws
A social-login integration links a local account to the wrong external identity. An attacker may gain access to another user's WordPress account.
What it looks like
A social-login integration links a local account to the wrong external identity.
Why it matters
An attacker may gain access to another user's WordPress account.
What to check
Review provider callbacks, state checks, and account-linking rules.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP authentication guidance.
- Categories: WordPress
- Tags: #WordPress Security, #Integrations