Junglewise Threat Intelligence

CVE-2026-19715: WP OAuth Server debug log information disclosure

CVE-2026-19715 · Severity: high · CVSS 7.5 · Published 2026-08-27

Vendors: miniOrange.

Executive brief

The WP OAuth Server WordPress plugin writes debug logs containing sensitive OAuth tokens, authorization codes, and user password hashes to a publicly accessible location without authentication. When debug logging is enabled, an attacker can read these files to obtain active credentials and impersonate users, leading to unauthorized access to user accounts and accounts linked through OAuth.

Technical details

The vulnerability is an information disclosure issue (CWE-200) caused by insufficient access controls on debug log files. The plugin stores logs at a fixed, web-accessible path (wp-content/uploads/miniorange-oauth-20-server/error-logs/wp_oauth_server_errors.log) without authentication or authorization checks. When debug logging is enabled, these logs contain unencrypted OAuth tokens, refresh tokens, authorization codes, and full WordPress user records including password hashes. An unauthenticated attacker can directly access this file via HTTP GET and retrieve active tokens to authenticate as any user who has completed an OAuth authorization flow. The vulnerability requires debug logging to be enabled but does not require network authentication or user interaction. Versions before 6.3.1 are affected; the issue is patched in 6.3.1.

Affected products

  • miniOrange WP OAuth Server before 6.3.1

Timeline

  • 2026-08-25: disclosed
  • 2026-08-27: advisory
  • 2026-08-25: patched: Fixed in version 6.3.1

References

Related threats