WP OAuth Server ( Login with WordPress ) <= 6.4.0 - Unauthenticated Missing Authorization to OAuth Client Registration via MCP Dynamic Client Registration Endpoint

Medium 6.8 CWE-862Fixed in 6.5.0
ID
WPSEC-2026-0738
Plugin
WP OAuth Server ( Login with WordPress ) (miniorange-oauth-20-server)
Affected
from 6.1.5 before 6.5.0
Remediation
Update to 6.5.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
WP OAuth Server ( Login with WordPress ) on WPSec AttackSurface
Fix released
Published

Description

The WP OAuth Server ( Login with WordPress ) plugin for WordPress is vulnerable to unauthorized OAuth client registration via the MCP Dynamic Client Registration REST endpoint (/mcp/register) in all versions from 6.1.5 up to, and including, 6.4.0. This is due to the endpoint being exposed without any authorization check whenever MCP is enabled and accepting arbitrary redirect URIs. This makes it possible for unauthenticated attackers, on sites with MCP enabled and no OAuth client yet configured, to register an OAuth client that redirects to an attacker-controlled URL and, by tricking a logged-in user into authorizing that client, obtain authorization codes and access tokens that can be used to access the site's MCP endpoint and user data as the victim.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0