Description
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
Published: 2026-07-29
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the miniOrange Social Login and Register plugin, in versions before 7.8.0, does not tie the one‑time code issued during its optional email‑verification (Profile Completion) feature to the specific user account for which the code was generated. An attacker who controls an email address can request a code for that address, capture the one‑time code, and then replay it against the email address of any target user on the site, including administrators, creating a valid session token. This flaw permits unauthenticated account takeover and allows an attacker to gain full account privileges without any password. The weakness corresponds to CWE‑287: Improper Authentication.

Affected Systems

WordPress users running the miniOrange Social Login and Register plugin before version 7.8.0 are affected. The flaw exists only when the Profile Completion feature is enabled and social login is configured. The plugin is distributed by miniOrange and is used in WordPress sites that integrate social login via Discord, Google, Twitter, and LinkedIn.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score of less than 1% shows a low current exploitation probability, and the issue is not listed in CISA KEV. Successful exploitation requires an attacker to be able to control an email address and to be able to trigger the Profile Completion feature on the target site, after which the attacker can replay the unused one‑time code to obtain a session. Because the attack is unauthenticated and can target any user, including administrators, the risk to organizations leveraging this plugin is high if the feature is enabled. The risk can be mitigated by disabling or removing the vulnerable feature or by updating the plugin to a fixed version.

Generated by OpenCVE AI on August 3, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the miniOrange Social Login and Register plugin to version 7.8.0 or later.
  • Disable the Profile Completion (email verification) feature until the plugin is updated.
  • Review and restrict access to social login configuration to trusted administrators.

Generated by OpenCVE AI on August 3, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Wordpress
Wordpress wordpress
Vendors & Products Miniorange
Miniorange wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
Title miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
References

Subscriptions

Miniorange Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T15:20:09.656Z

Reserved: 2026-07-01T10:48:09.848Z

Link: CVE-2026-14300

cve-icon Vulnrichment

Updated: 2026-07-30T15:14:32.533Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T07:16:41.857

Modified: 2026-07-30T16:16:55.673

Link: CVE-2026-14300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:00:03Z

Weaknesses