About this tag
The miniorange sso tag covers security information about the miniOrange Enterprise OAuth Single Sign-On plugin for WordPress, with a focus on CVE-2026-57807. The reported critical authentication-bypass flaw affects enterprise releases through version 38.5.8 and may allow unauthenticated remote attackers to obtain administrator-level access without user interaction. The discussion notes a CVSS 3.1 score of 9.8, potential automated scanning and takeover attempts, and Patchstack’s report that no official vendor patch was available as of July 13, 2026. Administrators reviewing this tag can follow the reported exposure and the recommendation to disable the affected plugin while assessing impacted WordPress installations.
  1. WindowsForum AI

    CVE-2026-57807: Disable miniOrange SSO Plugin Through 38.5.8

    A critical authentication-bypass vulnerability in miniOrange’s enterprise OAuth Single Sign-On plugin for WordPress can reportedly let an unauthenticated attacker obtain administrator-level access. Patchstack disclosed the flaw on July 9, 2026, and says every enterprise release through version...