Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation.

This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
Published: 2026-07-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Authentication Bypass Using an Alternate Path or Channel, classified as CWE-288. It allows an attacker to trigger the password recovery flow without authenticating, effectively bypassing normal login controls and enabling unauthorized resetting or acquisition of account credentials, thereby compromising the confidentiality of user accounts.

Affected Systems

The miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress, supplied by miniOrange Security Software Pvt Ltd., is affected in all releases up through version 38.5.8. Sites running any of these versions are vulnerable if the password recovery functionality remains exposed.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote web access to the plugin’s password recovery endpoint; the exact attack vector is not explicitly defined, but it is inferred to be possible through normal web interfaces.

Generated by OpenCVE AI on July 29, 2026 at 10:07 UTC.

Remediation

Vendor Solution

Update the WordPress OAuth Single Sign On - SSO (OAuth Client) plugin to the latest available version (at least 38.5.8.1).


OpenCVE Recommended Actions

  • Update the miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin to version 38.5.8.1 or later to eliminate the password recovery bypass.
  • If an update is not immediately available, remove or restrict the plugin’s password recovery page and add authentication checks so that only authenticated users can access it.
  • Apply rate limiting or enforce multi-factor authentication for account recovery to reduce the risk of automated abuse once recovery functionality is necessary.

Generated by OpenCVE AI on July 29, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange Security Software Pvt Ltd.
Miniorange Security Software Pvt Ltd. oauth Single Sign On - Sso (oauth Client)
Wordpress
Wordpress wordpress
Vendors & Products Miniorange Security Software Pvt Ltd.
Miniorange Security Software Pvt Ltd. oauth Single Sign On - Sso (oauth Client)
Wordpress
Wordpress wordpress

Fri, 10 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
Title WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Miniorange Security Software Pvt Ltd. Oauth Single Sign On - Sso (oauth Client)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-21T14:11:27.317Z

Reserved: 2026-06-25T08:05:16.223Z

Link: CVE-2026-57807

cve-icon Vulnrichment

Updated: 2026-07-13T14:01:14.604Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:15:06Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel