CVE-2015-9435: DASH10 OAuth Server
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
Affected products
- DASH10 OAuth Server: before 3.1.5 (fixed in 3.1.5)
Published 2019-09-26. Last modified 2026-06-17.