there's a second WordPress bug this month — and this one has no patch, just a plugin you need to switch off tonight

While everyone patched the wp2shell core flaw, a 9.8-rated hole in a popular login plugin quietly went public with no fix available. If you run…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

CVE-2026-57807 carries a CVSS score of 9.8 (Patchstack, the assigning CNA); NVD lists it as published July 10, 2026.

What you need to know

It affects miniOrange's OAuth SSO OAuth Client plugin from unspecified early versions through 38.5.8 — check your installed version now.

What you need to know

The flaw abuses an alternate authentication path in the password-recovery mechanism to bypass login entirely — no account, no interaction, low complexity.

What you need to know

Successful exploitation means full admin takeover: content injection, data theft, backdoors, lateral movement.

What you need to know

There was no official patch at disclosure. Deactivate the plugin or block it at a WAF until miniOrange ships a fixed release.

The 30-second version

Affected: miniOrange OAuth Single Sign-On (SSO OAuth Client), all versions up to and including 38.5.8. The bug: an authentication bypass abusing the password-recovery flow to log in as any user,…

Aliteq

Read the full story

there's a second WordPress bug this month — and this one has no patch, just a plugin you need to switch off tonight

Read the full story on Aliteq