CVE-2026-14300
HIGHminiOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
Title source: cnaDescription
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/7ecf657b-b059-4420-8c36-f38d58960d2b/
Scores
CVSS v3
8.1
EPSS
0.0014
EPSS Percentile
3.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
None/miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
< 7.8.0
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026