Description
WordPress Plugin WP OAuth Server (OAuth Authentication) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently predict authentication tokens. WordPress Plugin WP OAuth Server (OAuth Authentication) version 3.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.5 or latest
References
Related Vulnerabilities
Drupal Core 8.x Multiple Security Bypass Vulnerabilities (8.0.0 - 8.3.6)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2019-4156)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-1461)
WordPress Plugin YITH WooCommerce Multi-step Checkout Security Bypass (1.7.4)