# Patreon WordPress <= 1.9.17 - Cross-Site Request Forgery to Account Takeover via OAuth Callback

- **ID:** WPSEC-2026-0680
- **Plugin:** Patreon WordPress (`patreon-connect`), https://wordpress.org/plugins/patreon-connect/
- **Affected versions:** all versions before 1.10.0
- **Fixed in:** 1.10.0 (Update to 1.10.0 or later.)
- **Severity:** High 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- **Weakness:** CWE-352
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/patreon-connect
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0680/

## Description

The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.17 due to missing validation of the OAuth 'state' parameter in the Patreon OAuth callback handler, which links the Patreon account returned by the callback to the currently logged-in WordPress user. This makes it possible for unauthenticated attackers to link a logged-in victim's WordPress account to an attacker-controlled Patreon account via a forged request granted they can trick the victim into performing an action such as clicking a link, after which the attacker can log in as the victim using Login with Patreon. Administrator and editor accounts cannot log in with Patreon by default; when the victim is an administrator, the site's Patreon connection can be changed instead.

## References

- https://wpsec.com/vuln/WPSEC-2026-0680/
- https://plugins.svn.wordpress.org/patreon-connect/tags/1.10.0/
- https://wordpress.org/plugins/patreon-connect/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0680/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
