Popis
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim-s email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
CVSS 8.1EPSS 0.23900000000000002%Riziko 0.83
Zobraziť zdroj- Zverejnené
- 2026-07-29 07:16:41
- Dotknuté verzie
- <7.8.0
- Typ
- Webová aplikácia
- Posledná úprava
- 2026-07-30 16:16:55
- Vektor
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H