CVE-2025-9485 | OAuth Single Sign On Plugin up to 6.26.12 on WordPress get_resource_owner_from_id_token improper authentication
A vulnerability was found in OAuth Single Sign On Plugin up to 6.26.12 on WordPress and classified as critical. Affected is the function get_resource_owner_from_id_token. Executing manipulation can lead to improper authentication.
The identification of this vulnerability is CVE-2025-9485. The attack may be launched remotely. There is no exploit available.