Περιγραφή
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim-s email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
CVSS 8.1EPSS 0.23900000000000002%Κίνδυνος 0.83
Προβολή πηγής- Δημοσίευση
- 2026-07-29 07:16:41
- Επηρεαζόμενες εκδόσεις
- <7.8.0
- Τύπος
- Εφαρμογή ιστού
- Τελευταία τροποποίηση
- 2026-07-30 16:16:55
- Διάνυσμα
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H