← Zurück zur CVE-Suche

CVE-2026-14300

miniOrange Social Login and Register

Beschreibung

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim-s email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.

CVSS 8.1EPSS 0.23900000000000002%Risiko 0.83
Quelle öffnen
Veröffentlicht
2026-07-29 07:16:41
Betroffene Versionen
<7.8.0
Typ
Webanwendung
Zuletzt geändert
2026-07-30 16:16:55
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H