miniOrange: Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website

miniOrange: Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website

Critical WordPress OAuth Plugin Flaw Exposes Millions of Sites to Full Takeover

A severe security vulnerability in the miniOrange OAuth Single Sign-On (SSO) plugin for WordPress has left millions of websites vulnerable to unauthenticated remote takeover. Tracked as CVE-2026-57807 with a CVSS score of 9.8, the flaw was disclosed by Patchstack on July 9, 2026, and classified under OWASP A7: Identification and Authentication Failures.

The issue stems from a Broken Authentication weakness (CWE-288), specifically exploiting the plugin’s password recovery mechanism via an alternate authentication pathway. Attackers can bypass login controls without prior access, authentication, or user interaction, making exploitation trivial and low-complexity. All versions of the plugin up to and including 38.5.8 are affected.

Successful exploitation allows attackers to impersonate any WordPress user, including administrators, leading to full site compromise. Potential consequences include malicious content injection, data exfiltration, backdoor installation, and lateral movement within the hosting environment.

Patchstack warns the flaw is highly likely to be exploited in mass campaigns, targeting websites regardless of size or traffic. While no official patch has been released by miniOrange, Patchstack has issued a virtual patch to block attacks until a fix is available.

Security researcher Kim Dvash reported the vulnerability on June 6, 2026, with the NVD publishing the CVE on July 10, 2026. Administrators are advised to deactivate and remove the plugin from exposed WordPress installations or restrict access to login and recovery endpoints via WAF rules or IP allowlisting as a temporary mitigation. Updates should be applied immediately upon release.

Source: https://cybersecuritynews.com/wordpress-plugin-vulnerability-miniorange/

miniOrange cybersecurity rating report: https://www.rankiteo.com/company/miniorange

"id": "MIN1783945821",
"linkid": "miniorange",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Global',
                        'name': 'WordPress sites using miniOrange OAuth SSO '
                                'plugin',
                        'size': 'Millions of sites',
                        'type': 'Websites'}],
 'attack_vector': 'Remote',
 'data_breach': {'data_exfiltration': 'Potential'},
 'date_detected': '2026-06-06',
 'date_publicly_disclosed': '2026-07-09',
 'description': 'A severe security vulnerability in the miniOrange OAuth '
                'Single Sign-On (SSO) plugin for WordPress has left millions '
                'of websites vulnerable to unauthenticated remote takeover. '
                'The flaw, tracked as CVE-2026-57807 with a CVSS score of 9.8, '
                'allows attackers to bypass login controls without prior '
                'access, authentication, or user interaction, leading to full '
                'site compromise.',
 'impact': {'data_compromised': 'Potential data exfiltration',
            'operational_impact': 'Full site compromise, malicious content '
                                  'injection, backdoor installation, lateral '
                                  'movement',
            'systems_affected': 'WordPress sites using miniOrange OAuth SSO '
                                'plugin (versions up to and including 38.5.8)'},
 'initial_access_broker': {'backdoors_established': 'Potential backdoor '
                                                    'installation'},
 'post_incident_analysis': {'corrective_actions': 'Apply official patch upon '
                                                  'release, restrict access to '
                                                  'vulnerable endpoints',
                            'root_causes': 'Broken Authentication (CWE-288) in '
                                           'the plugin’s password recovery '
                                           'mechanism via an alternate '
                                           'authentication pathway'},
 'recommendations': 'Deactivate and remove the plugin from exposed WordPress '
                    'installations or restrict access to login and recovery '
                    'endpoints via WAF rules or IP allowlisting as a temporary '
                    'mitigation. Apply updates immediately upon release.',
 'references': [{'date_accessed': '2026-07-09', 'source': 'Patchstack'},
                {'date_accessed': '2026-07-10', 'source': 'NVD'}],
 'response': {'containment_measures': 'Deactivate and remove the plugin, '
                                      'restrict access to login and recovery '
                                      'endpoints via WAF rules or IP '
                                      'allowlisting',
              'remediation_measures': 'Apply official patch upon release',
              'third_party_assistance': 'Patchstack (virtual patch)'},
 'title': 'Critical WordPress OAuth Plugin Flaw Exposes Millions of Sites to '
          'Full Takeover',
 'type': 'Authentication Bypass',
 'vulnerability_exploited': 'CVE-2026-57807 (Broken Authentication - CWE-288)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.