# WP OAuth Server ( Login with WordPress ) <= 6.4.0 - Unauthenticated Missing Authorization to OAuth Client Registration via MCP Dynamic Client Registration Endpoint

- **ID:** WPSEC-2026-0738
- **Plugin:** WP OAuth Server ( Login with WordPress ) (`miniorange-oauth-20-server`), https://wordpress.org/plugins/miniorange-oauth-20-server/
- **Affected versions:** from 6.1.5 before 6.5.0
- **Fixed in:** 6.5.0 (Update to 6.5.0 or later.)
- **Severity:** Medium 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/miniorange-oauth-20-server
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0738/

## Description

The WP OAuth Server ( Login with WordPress ) plugin for WordPress is vulnerable to unauthorized OAuth client registration via the MCP Dynamic Client Registration REST endpoint (/mcp/register) in all versions from 6.1.5 up to, and including, 6.4.0. This is due to the endpoint being exposed without any authorization check whenever MCP is enabled and accepting arbitrary redirect URIs. This makes it possible for unauthenticated attackers, on sites with MCP enabled and no OAuth client yet configured, to register an OAuth client that redirects to an attacker-controlled URL and, by tricking a logged-in user into authorizing that client, obtain authorization codes and access tokens that can be used to access the site's MCP endpoint and user data as the victim.

## References

- https://wpsec.com/vuln/WPSEC-2026-0738/
- https://plugins.svn.wordpress.org/miniorange-oauth-20-server/tags/6.5.0/
- https://wordpress.org/plugins/miniorange-oauth-20-server/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0738/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
