云虫漏洞库

CVE-2026-19715 - The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled. - 漏洞详情

漏洞编号:CVE-2026-19715

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-19715

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-200

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.

相关链接

相关漏洞

« 返回首页