Sunday, September 6, 2026

Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access

A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8.

This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.

Critical WordPress OAuth SSO Plugin Flaw

Discovered by security researcher Kim Dvash and reported on June 6, 2026, the vulnerability was published in the Patchstack database on July 9, 2026.

Classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and mapped to OWASP A7: Identification and Authentication Failures, the flaw exploits the plugin’s password recovery mechanism. This mechanism represents an alternate authentication pathway that fails to enforce login controls properly.

The CVSS 3.1 vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates the extreme risk level: the attack is fully network-based, requires no privileges, and demands zero user interaction, allowing for complete compromise of confidentiality, integrity, and availability.

Successful exploitation allows an unauthenticated remote attacker to bypass authentication entirely and log in as any registered WordPress user, including site administrators.

This can lead to a complete site takeover, malicious content injection, data exfiltration, and lateral movement within the hosting environment. The exploit leverages the plugin’s password recovery flow, CAPEC-50: Password Recovery Exploitation, which can be triggered remotely with low complexity, making it easy to exploit on a large scale.

Patchstack has flagged this vulnerability as a High Priority issue, cautioning that vulnerabilities of this nature are frequently exploited in mass campaigns that indiscriminately target thousands of WordPress sites, regardless of their traffic volume or public visibility.

As of July 10, 2026, there is no official patch available from miniOrange. Patchstack has implemented a virtual patching (WAF) rule to block both legitimate and malicious exploitation attempts, providing temporary protection for sites using Patchstack while they wait for an official fix.

Site administrators running the affected plugin are urged to take the following immediate actions:

  • Deactivate and remove the plugin from all publicly accessible WordPress installations until a patched version is released.
  • Apply WAF rules or IP-based allowlisting to restrict access to login and password recovery endpoints if immediate removal is not feasible.
  • Monitor the official WordPress plugin repository for a patched release and apply updates promptly.
  • Track suspicious password recovery attempts in server and access logs.

The miniOrange OAuth SSO plugin has a documented history of authentication-related vulnerabilities, including a prior authentication bypass (CVE-2024-10111, CVSS 8.1) disclosed in December 2024. This recurring pattern highlights the need for rigorous security reviews of OAuth integration plugins, which hold a highly privileged position within the WordPress authentication stack.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News