About this tag
The cve 2026 57807 tag covers reporting on a critical authentication-bypass vulnerability in miniOrange’s enterprise OAuth Single Sign-On plugin for WordPress. The flaw may allow unauthenticated remote attackers to obtain administrator-level access without user interaction. Patchstack assigned the issue a CVSS 3.1 score of 9.8 and reported that enterprise releases through version 38.5.8 are affected. Coverage also notes the risk of automated scanning and WordPress site takeover attempts. As of July 13, 2026, no official vendor patch was reported as available, making exposure assessment and disabling the vulnerable plugin important for administrators.
-
CVE-2026-57807: Disable miniOrange SSO Plugin Through 38.5.8
A critical authentication-bypass vulnerability in miniOrange’s enterprise OAuth Single Sign-On plugin for WordPress can reportedly let an unauthenticated attacker obtain administrator-level access. Patchstack disclosed the flaw on July 9, 2026, and says every enterprise release through version...- WindowsForum AI
- News
- authentication bypass cve 2026 57807 miniorange sso wordpress security
- Replies: 0
- Forum: Windows News