CVE-2026-28008
9.8miniOrange · OAuth Single Sign On – SSO (OAuth Client)
The miniOrange OAuth Single Sign On plugin for WordPress contains an unauthenticated authentication bypass vulnerability that allows attackers to spoof identities.
Executive summary
An unauthenticated authentication bypass vulnerability in the miniOrange OAuth Single Sign On plugin enables attackers to spoof user sessions and gain unauthorized access.
Vulnerability
This is an authentication bypass vulnerability (CWE-290) stemming from improper verification of OAuth responses. The flaw allows unauthenticated remote attackers to manipulate the authentication flow and gain unauthorized access to the application.
Business impact
Successful exploitation results in unauthorized access to the WordPress environment, potentially allowing attackers to impersonate administrative users. With a CVSS score of 9.8, this represents a critical risk to the security of the entire web application, including sensitive user data and configuration settings.
Remediation
Immediate Action: Update the miniOrange OAuth Single Sign On plugin to version 7.0.1 or later immediately.
Proactive Monitoring: Monitor authentication logs for unusual login patterns or sessions created without corresponding OAuth handshake activity.
Compensating Controls: If an update cannot be performed immediately, deactivate the plugin to prevent unauthorized access until a patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw necessitates an immediate update to the plugin. Administrators should treat this as a high-priority task, as the bypass allows for total compromise of the authentication mechanism, which is a cornerstone of site security.