Patreon WordPress <= 1.9.17 - Cross-Site Request Forgery to Account Takeover via OAuth Callback

High 8.1 CWE-352Fixed in 1.10.0
ID
WPSEC-2026-0680
Plugin
Patreon WordPress (patreon-connect)
Affected
all versions before 1.10.0
Remediation
Update to 1.10.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness
CWE-352
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Patreon WordPress on WPSec AttackSurface
Fix released
Published

Description

The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.17 due to missing validation of the OAuth 'state' parameter in the Patreon OAuth callback handler, which links the Patreon account returned by the callback to the currently logged-in WordPress user. This makes it possible for unauthenticated attackers to link a logged-in victim's WordPress account to an attacker-controlled Patreon account via a forged request granted they can trick the victim into performing an action such as clicking a link, after which the attacker can log in as the victim using Login with Patreon. Administrator and editor accounts cannot log in with Patreon by default; when the victim is an administrator, the site's Patreon connection can be changed instead.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0