CVE-2026-28008

9.8

miniOrange · OAuth Single Sign On – SSO (OAuth Client)

The miniOrange OAuth Single Sign On plugin for WordPress contains an unauthenticated authentication bypass vulnerability that allows attackers to spoof identities.

Executive summary

An unauthenticated authentication bypass vulnerability in the miniOrange OAuth Single Sign On plugin enables attackers to spoof user sessions and gain unauthorized access.

Vulnerability

This is an authentication bypass vulnerability (CWE-290) stemming from improper verification of OAuth responses. The flaw allows unauthenticated remote attackers to manipulate the authentication flow and gain unauthorized access to the application.

Business impact

Successful exploitation results in unauthorized access to the WordPress environment, potentially allowing attackers to impersonate administrative users. With a CVSS score of 9.8, this represents a critical risk to the security of the entire web application, including sensitive user data and configuration settings.

Remediation

Immediate Action: Update the miniOrange OAuth Single Sign On plugin to version 7.0.1 or later immediately.

Proactive Monitoring: Monitor authentication logs for unusual login patterns or sessions created without corresponding OAuth handshake activity.

Compensating Controls: If an update cannot be performed immediately, deactivate the plugin to prevent unauthorized access until a patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw necessitates an immediate update to the plugin. Administrators should treat this as a high-priority task, as the bypass allows for total compromise of the authentication mechanism, which is a cornerstone of site security.

More miniOrange CVEs