TGViewer
Netlas.io Netlas.io @netlas · 2.32K subscribers
Post #593 573
CVE-2026-57807 & CVE-2026-12761: Two vulnerable WordPress plugins by miniOrange, 9.8 rating both 🔥

There are two authentication bypass vulnerabilities disclosed in miniOrange plugins: OAuth Single Sign On - SSO & Social Login and Register (Discord, Google, Twitter, LinkedIn). These flaws might allow a malicious actor to gain admin access to the website.

Search at Netlas.io:
👉 Link: https://nt.ls/M4c8B
👉 Dork: http.body:"plugins/miniorange-oauth-oidc-single-sign-on" OR http.body:"miniorange-login-openid"

Read more:
https://patchstack.com/database/wordpress/plugin/miniorange-oauth-oidc-single-sign-on/vulnerability/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-38-5-8-broken-authentication-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-login-openid/miniorange-social-login-and-register-discord-google-twitter-linkedin-770-unauthenticated-authentication-bypass-to-administrator-account-takeover-via-profile-completion-otp-flow
  • 🔥 4
  • ❤ 3
More from @netlas
  1. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
  2. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  3. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  4. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  5. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  6. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →