Critical WordPress Plugin Lets Hackers In as Admin
A critical flaw in the miniOrange OAuth SSO plugin (CVSS 9.8) lets unauthenticated attackers log in as WordPress administrator with no password. No official patch has been released. Here is what to do right now.
August 8, 2026
Security Updates & Threats