WP OAuth Server ( Login with WordPress ) <= 6.4.0 - Unauthenticated Missing Authorization to OAuth Client Registration via MCP Dynamic Client Registration Endpoint
- ID
- WPSEC-2026-0738
- Plugin
- WP OAuth Server ( Login with WordPress ) (miniorange-oauth-20-server)
- Affected
- from 6.1.5 before 6.5.0
- Remediation
- Update to 6.5.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- WP OAuth Server ( Login with WordPress ) on WPSec AttackSurface
- Fix released
- Published
Description
The WP OAuth Server ( Login with WordPress ) plugin for WordPress is vulnerable to unauthorized OAuth client registration via the MCP Dynamic Client Registration REST endpoint (/mcp/register) in all versions from 6.1.5 up to, and including, 6.4.0. This is due to the endpoint being exposed without any authorization check whenever MCP is enabled and accepting arbitrary redirect URIs. This makes it possible for unauthenticated attackers, on sites with MCP enabled and no OAuth client yet configured, to register an OAuth client that redirects to an attacker-controlled URL and, by tricking a logged-in user into authorizing that client, obtain authorization codes and access tokens that can be used to access the site's MCP endpoint and user data as the victim.
References
- https://wpsec.com/vuln/WPSEC-2026-0738/
- https://plugins.svn.wordpress.org/miniorange-oauth-20-server/tags/6.5.0/
- https://wordpress.org/plugins/miniorange-oauth-20-server/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS