The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
Link | Tags |
---|---|
https://wordpress.org/plugins/oauth2-provider/#developers | product vendor advisory |
https://security.dxw.com/advisories/the-oauth2-complete-plugin-for-wordpress-uses-a-pseudorandom-number-generator-which-is-non-cryptographically-secure/ | third party advisory |