Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Developer)
  3. Urgent Security update for OIDC plugin Wordpress

Urgent Security update for OIDC plugin Wordpress

Scheduled Pinned Locked Moved Unsolved WordPress (Developer)
wordpressoidcsecurity
3 Posts 2 Posters 23 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • imc67I Offline
    imc67I Offline
    imc67
    translator
    wrote last edited by imc67
    #1

    https://wordpress.org/plugins/daggerhart-openid-connect-generic/

    Update 3.11.1
    After manual update:

    OpenID Connect Generic - Security Configuration Required

    Your OpenID Connect authentication is using an insecure fallback method. You must configure the JWKS endpoint in plugin settings as soon as possible.
    
    The current insecure fallback will be removed in version 3.12.0. After that update, authentication will fail until the JWKS endpoint is configured.
    
    Common JWKS endpoints:
    • Keycloak: https://your-domain/realms/your-realm/protocol/openid-connect/certs
    • Auth0: https://your-domain.auth0.com/.well-known/jwks.json
    • Okta: https://your-domain.okta.com/oauth2/default/v1/keys
    • Azure AD: https://login.microsoftonline.com/your-tenant/discovery/v2.0/keys
    • Google: https://www.googleapis.com/oauth2/v3/certs
    

    I tried to manually update within Wordpress Developer app but login got broken, had to restore.

    3.11.0

    SECURITY RELEASE

    Security: Added JWT signature verification using JWKS to prevent token forgery
    Security: Enhanced token claim validation (exp, aud, iss, iat, nonce)
    Security: Replaced weak state generation with cryptographically secure random_bytes()
    Security: Fixed open redirect vulnerability in authentication flow
    Security: Restricted SSL verification bypass to local development environments only
    Security: Added nonce protection to debug mode to prevent information disclosure
    Security: Added SSRF protection by default through use of wp_safe_remote_* functions
    Feature: Added JWKS endpoint configuration setting
    Feature: Added OpenID Connect discovery document support
    Feature: Added customizable login button text setting
    Improvement: Migrated to Composer-managed dependencies
    Fix: Corrected issuer validation to properly extract base URL from endpoints
    Fix: Identity token timestamp tracking

    1 Reply Last reply
    1
    • girishG girish moved this topic from Support
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote last edited by
      #2

      The current plugin version has some issues, I have left a note here - https://github.com/oidc-wp/openid-connect-generic/issues/633

      1 Reply Last reply
      1
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote last edited by
        #3

        The plugin has also started requiring the 'alg' param in JWKS keys. The field is optional (https://datatracker.ietf.org/doc/html/rfc7517#section-4.4) , but I have added it to our oidcserver now.

        1 Reply Last reply
        0
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search