miniOrange Social Login and Register: Privilege Escalation (CVSS 9.8)

Introduction

miniOrange Social Login and Register — a separate plugin from the same vendor’s OAuth SSO product — had a critical privilege escalation vulnerability disclosed in July 2026, rated CVSS 9.8. If you run any miniOrange login/authentication plugin, it’s worth checking your full plugin list rather than assuming a fix for one product covers another.

What You Should Do Right Now

  1. Check exactly which miniOrange plugin(s) you have installed — “Social Login and Register” and “OAuth Single Sign-On” are different products with separate vulnerabilities and separate fixes.
  2. Back up your site before applying any update.
  3. Update to the patched version as soon as it’s confirmed available for your specific plugin.
  4. Review your admin user list for unfamiliar accounts, the usual sign of a privilege escalation bug already being exploited.

Why Vendor-Wide Awareness Matters

When a vendor has multiple plugins with similar names and overlapping functionality, it’s easy to patch one and assume you’re covered. This pair of miniOrange disclosures in the same month is a good reminder to check every plugin from a given vendor when one of their products makes security news, not just the one mentioned in the headline.

FAQ

Is this the same bug as the miniOrange OAuth SSO issue?
No — it’s a separate plugin and a separate vulnerability, disclosed around the same time. Both need to be checked and patched independently.

How do I tell my miniOrange plugins apart?
Go to Plugins in wp-admin and read the exact plugin name and author — “OAuth Single Sign-On,” “Social Login and Register,” and other miniOrange products are listed separately.

What should I check for unauthorized access?
Review your Users list for any administrator accounts you didn’t create, and check recent login activity if your security plugin logs it.

Conclusion

Two critical bugs from the same vendor in the same month is a signal to check your entire plugin list for that vendor, not just patch the one you heard about.

A safe rollback point for every update

Nota Backup & Restore keeps automatic, off-site backups so you can update with confidence — and recover fast if something’s already wrong. Start your 14-day free trial — no credit card required.