# WordPress OAuth SSO plugin JWT bypass, admin takeover

Source: https://startwithidentity.com/cves/cve-2025-9485/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

The OAuth SSO plugin for WordPress (through 6.26.12) did not verify [JWT](https://startwithidentity.com/glossary/jwt/) signatures correctly. An attacker could mint a token and become an administrator. Fixed in 6.26.13.

## Why it matters

WordPress is not an IdP, but it is often the first SSO-enabled public site a company ships. A plugin that "adds OAuth" and then skips signature checks is how a marketing CMS becomes a privileged foothold. The same class as [node-jws](https://startwithidentity.com/cves/cve-2025-65945/) and [SimpleHelp](https://startwithidentity.com/cves/cve-2026-48558/): the token is trusted because it looks like a token.

## What to do

- Update the plugin to 6.26.13 or later. If you cannot, disable SSO on that site.
- Review WordPress administrator accounts created around the disclosure window.
- Do not point production [OIDC](https://startwithidentity.com/glossary/oidc/) at a plugin you have not seen verify signatures against a JWKS.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-9485](https://nvd.nist.gov/vuln/detail/CVE-2025-9485)
