Patreon WordPress <= 1.9.17 - Cross-Site Request Forgery to Account Takeover via OAuth Callback
- ID
- WPSEC-2026-0680
- Plugin
- Patreon WordPress (patreon-connect)
- Affected
- all versions before 1.10.0
- Remediation
- Update to 1.10.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Weakness
- CWE-352
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Patreon WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.17 due to missing validation of the OAuth 'state' parameter in the Patreon OAuth callback handler, which links the Patreon account returned by the callback to the currently logged-in WordPress user. This makes it possible for unauthenticated attackers to link a logged-in victim's WordPress account to an attacker-controlled Patreon account via a forged request granted they can trick the victim into performing an action such as clicking a link, after which the attacker can log in as the victim using Login with Patreon. Administrator and editor accounts cannot log in with Patreon by default; when the victim is an administrator, the site's Patreon connection can be changed instead.
References
- https://wpsec.com/vuln/WPSEC-2026-0680/
- https://plugins.svn.wordpress.org/patreon-connect/tags/1.10.0/
- https://wordpress.org/plugins/patreon-connect/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS