A critical broken authentication flaw tracked as CVE-2026-57807 affects the miniOrange OAuth Single Sign On - SSO (OAuth Client) WordPress plugin and allows unauthenticated remote attackers to compromise vulnerable sites. The issue impacts plugin versions through 38.5.8 and is classified as CWE-288. According to public reporting and the CVE entry, the bug abuses the plugin's password recovery flow to let an attacker authenticate as arbitrary WordPress users, including administrators, creating a direct path to full website takeover.
The vulnerability carries a CVSS 9.8 rating and is considered low complexity and remotely exploitable with no user interaction required. Patchstack disclosed the issue and warned it is likely to face mass exploitation, while noting that no official vendor patch was available at the time of reporting. Defenders were urged to immediately remove the affected plugin or limit exposure to WordPress login and password recovery endpoints until miniOrange releases a fix; Patchstack also said it had issued a virtual patch for protected customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE feed entry states that CVE-2026-57807 was newly received by Patchstack on July 10, 2026. The vulnerability was recorded as a broken authentication issue enabling password recovery exploitation in the miniOrange OAuth Single Sign On - SSO (OAuth Client) WordPress plugin through version 38.5.8.
Patchstack disclosed a critical broken authentication vulnerability, CVE-2026-57807, in the miniOrange WordPress OAuth Single Sign-On (SSO (OAuth Client)) plugin on July 9, 2026. The flaw affects versions through 38.5.8, no official vendor fix was available at the time, and Patchstack released a virtual patch while warning the issue was likely to be mass exploited.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.