WordPress OpenID Connect Generic Client plugin 3.8.0 and 3.8.1 contains a cross-site scripting vulnerability. It does not sanitize the login error when output back in the login form, thereby not requiring authentication, which can be exploited with the default configuration.
id: CVE-2021-24214
info:
name: WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site S
...