A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8.
This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.
Critical WordPress OAuth SSO Plugin Flaw
Discovered by security researcher Kim Dvash and reported on June 6, 2026, the vulnerability was published in the Patchstack database on July 9, 2026.
Classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and mapped to OWASP A7: Identification and Authentication Failures, the flaw exploits the plugin’s password recovery mechanism. This mechanism represents an alternate authentication pathway that fails to enforce login controls properly.
The CVSS 3.1 vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates the extreme risk level: the attack is fully network-based, requires no privileges, and demands zero user interaction, allowing for complete compromise of confidentiality, integrity, and availability.
Successful exploitation allows an unauthenticated remote attacker to bypass authentication entirely and log in as any registered WordPress user, including site administrators.
This can lead to a complete site takeover, malicious content injection, data exfiltration, and lateral movement within the hosting environment. The exploit leverages the plugin’s password recovery flow, CAPEC-50: Password Recovery Exploitation, which can be triggered remotely with low complexity, making it easy to exploit on a large scale.
Patchstack has flagged this vulnerability as a High Priority issue, cautioning that vulnerabilities of this nature are frequently exploited in mass campaigns that indiscriminately target thousands of WordPress sites, regardless of their traffic volume or public visibility.
As of July 10, 2026, there is no official patch available from miniOrange. Patchstack has implemented a virtual patching (WAF) rule to block both legitimate and malicious exploitation attempts, providing temporary protection for sites using Patchstack while they wait for an official fix.
Site administrators running the affected plugin are urged to take the following immediate actions:
- Deactivate and remove the plugin from all publicly accessible WordPress installations until a patched version is released.
- Apply WAF rules or IP-based allowlisting to restrict access to login and password recovery endpoints if immediate removal is not feasible.
- Monitor the official WordPress plugin repository for a patched release and apply updates promptly.
- Track suspicious password recovery attempts in server and access logs.
The miniOrange OAuth SSO plugin has a documented history of authentication-related vulnerabilities, including a prior authentication bypass (CVE-2024-10111, CVSS 8.1) disclosed in December 2024. This recurring pattern highlights the need for rigorous security reviews of OAuth integration plugins, which hold a highly privileged position within the WordPress authentication stack.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN





