PT-2026-57307 · WordPress · Miniorange Oauth Single Sign On – Sso

CVE-2026-57807

·

Published

2026-07-09

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions miniOrange OAuth Single Sign On - SSO (OAuth Client) versions prior to 38.5.9
Description An authentication bypass exists in the miniOrange OAuth SSO WordPress plugin. An unauthenticated remote attacker can exploit an alternate password-recovery path that fails to properly enforce authentication, which can lead to full account takeover.
Recommendations Disable the plugin as a temporary mitigation measure. Update to the version released after 38.5.8.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57807

Affected Products

Miniorange Oauth Single Sign On – Sso