CVE-2026-14300

HIGH

miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover

Title source: cna
STIX 2.1

Description

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7ecf657b-b059-4420-8c36-f38d58960d2b/

Scores

CVSS v3 8.1
EPSS 0.0014
EPSS Percentile 3.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
None/miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) < 7.8.0
Published Jul 29, 2026
Tracked Since Jul 29, 2026