### [CVE-2022-3632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3632) ![](https://img.shields.io/static/v1?label=Product&message=OAuth%20Client%20by%20DigitialPixies&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.1.0%3C%3D%201.1.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-352%20Cross-Site%20Request%20Forgery%20(CSRF)&color=brighgreen) ### Description The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions. ### POC #### Reference - https://wpscan.com/vulnerability/4c1b0e5e-245a-4d1f-a561-e91af906e62d #### Github No PoCs found on GitHub currently.