Introduction
A critical authentication bypass vulnerability, CVE-2026-57807, was disclosed on July 9, 2026 in the miniOrange OAuth Single Sign-On plugin. It carries a near-maximum CVSS score of 9.8 and lets an unauthenticated attacker bypass login entirely by abusing a flaw in the plugin’s password recovery mechanism — no account, no user interaction, no prior access required.
All versions up to and including 38.5.8 are affected. As of this writing, miniOrange has not shipped an official patch — Patchstack has released a virtual patch for its customers to block exploitation in the meantime.
What You Should Do Right Now
- Check if you’re running this plugin. Go to Plugins in wp-admin and search for “miniOrange OAuth Single Sign-On.”
- Take a full backup immediately before making any changes — especially important here since there’s no official fix yet to simply update into.
- Apply a virtual patch or WAF rule if your security plugin or host offers one for CVE-2026-57807.
- Consider temporarily deactivating the plugin if SSO login isn’t business-critical, until an official patch ships.
- Review your user list for any admin accounts you don’t recognize — a classic sign this bypass has already been used.
Why This One Is Different
Most of the alerts on this page involve a patch you can apply right away. This one doesn’t — which means the backup you take today isn’t just a precaution before an update, it’s your safety net for however long you’re running exposed. If mitigation fails or the plugin needs to come out entirely, having a clean, recent, off-site backup means that decision doesn’t turn into a bigger outage.
FAQ
Is there an official fix yet?
Not at the time of writing. Check the plugin’s changelog in wp-admin regularly, or watch for updates on Patchstack’s vulnerability database.
What does “authentication bypass” actually mean here?
An attacker can trick the plugin’s password recovery flow into granting access without ever knowing a real password — effectively logging in as any user, including an admin.
Should I just delete the plugin?
If your site doesn’t depend on OAuth SSO login for daily operations, deactivating it until a patch ships is the safest option.
Conclusion
An unpatched, unauthenticated 9.8-severity bypass is about as serious as it gets. Back up, mitigate or deactivate, and keep checking for the official fix.
Don’t wait for a patch to protect your site
Nota Backup & Restore keeps automatic, off-site backups so you can recover fast if a vulnerability like this gets exploited before a fix ships. Start your 14-day free trial — no credit card required.
