{
 "id": "WPSEC-2026-0680",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0680/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0680/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0680/index.md",
 "title": "Patreon WordPress <= 1.9.17 - Cross-Site Request Forgery to Account Takeover via OAuth Callback",
 "description": "The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.17 due to missing validation of the OAuth 'state' parameter in the Patreon OAuth callback handler, which links the Patreon account returned by the callback to the currently logged-in WordPress user. This makes it possible for unauthenticated attackers to link a logged-in victim's WordPress account to an attacker-controlled Patreon account via a forged request granted they can trick the victim into performing an action such as clicking a link, after which the attacker can log in as the victim using Login with Patreon. Administrator and editor accounts cannot log in with Patreon by default; when the victim is an administrator, the site's Patreon connection can be changed instead.",
 "plugin": {
  "slug": "patreon-connect",
  "name": "Patreon WordPress",
  "full_name": "Patreon WordPress",
  "wordpress_org": "https://wordpress.org/plugins/patreon-connect/",
  "advisories_url": "https://wpsec.com/vuln/plugin/patreon-connect/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/patreon-connect"
 },
 "type": "CSRF",
 "cwe": [
  "CWE-352"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.10.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.10.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.10.0",
 "remediation": "Update to 1.10.0 or later.",
 "fix_released": "2026-10-07T21:08:00+00:00",
 "published": "2026-10-08T21:46:21+00:00",
 "updated": "2026-10-08T07:40:41.035435+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0680/",
  "https://plugins.svn.wordpress.org/patreon-connect/tags/1.10.0/",
  "https://wordpress.org/plugins/patreon-connect/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/patreon-connect",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}