Critical WordPress Plugin Lets Hackers In as Admin

If your website runs on WordPress and uses a plugin to let staff sign in with their Microsoft or Google accounts, there is a serious security issue you need to act on today.

A critical flaw has been disclosed in the miniOrange OAuth Single Sign-On (SSO) plugin, tracked as CVE-2026-57807, and disclosed by security firm Patchstack on 9 July 2026. It carries a CVSS score of 9.8 out of 10 — near the maximum possible severity rating.

Single sign-on, or SSO, is what lets users log into a website using credentials from another service — for example, “Sign in with Microsoft” or “Sign in with Google”. It is a common setup for businesses where staff need to access a company website or intranet using the same accounts they already use for email and documents. The miniOrange plugin handles exactly this for WordPress sites.

What the flaw does

The vulnerability exploits the plugin’s password recovery mechanism in a way that allows a complete stranger — someone with no account and no password — to log in as an administrator. No user interaction is required. No existing account is needed. An attacker sends a crafted request and the plugin grants admin access.

All versions up to and including version 38.5.8 are affected.

Why this matters to your business

WordPress administrator access gives an attacker full control of a website. They can read or delete content, harvest visitor data, inject malicious code, or redirect visitors to harmful sites. For businesses that take enquiries, bookings, or payments through their website, or that store customer data, the consequences can include data breaches and regulatory penalties under UK GDPR.

A CVSS score of 9.8 also means this type of flaw is a prime target for automated scanning tools that sweep millions of sites at once. You do not need to be individually targeted to be at risk.

Is there a fix?

At the time of writing, miniOrange had not released an official patch. We recommend checking the plugin’s WordPress repository page for any update released since this post was written.

Patchstack has released a virtual patch — a web application firewall (WAF) rule that blocks exploitation attempts on its platform — as a temporary measure while the vendor works on a fix. This is useful if you need to keep the SSO functionality running in the short term, but disabling the plugin entirely is the safest option until a proper fix is available.

What we have done

We have reviewed all WordPress sites under our management to check whether this plugin is installed and active. Where it is present, we have either disabled it or applied a protective control while awaiting a vendor fix. If you are an existing System Force IT client with questions about your website, please get in touch.

What you should check or do

  • Check for the plugin: Log in to your WordPress dashboard, go to Plugins, and search for “miniOrange” or “OAuth Single Sign-On”. If you find it, check the version number.
  • Disable the plugin immediately if you are running version 38.5.8 or earlier. Staff will need to log in via their WordPress username and password as a temporary workaround.
  • Check for unexpected admin accounts: Go to Users, filter by the Administrator role, and remove any accounts you do not recognise.
  • Look for signs of compromise: Check for new or changed pages, unexpected file uploads, or unfamiliar code added to your theme or other plugins.
  • Update as soon as a patch is available: Monitor the plugin’s repository page and apply the fix as soon as it appears.

The broader picture

This disclosure follows closely on the wp2shell vulnerability in WordPress core covered in our post last week. That was a flaw in WordPress itself; CVE-2026-57807 is a plugin-level issue. Two serious vulnerabilities in quick succession is a reminder that the security of your website depends not just on keeping WordPress up to date, but on actively auditing every plugin that is installed.

Plugins are one of the most common entry points attackers use, because they are often installed and then forgotten. A regular security review of your site — checking for unused or outdated plugins, reviewing user accounts, and confirming your WAF and backup processes are working — significantly reduces your exposure.

Active security management of your website is part of what our IT security services cover. System Force IT holds UKAS-accredited ISO/IEC 27001 certification and provides managed IT services to businesses across Gloucestershire and the wider UK. If your website has not had a security review recently, or you would like us to assess your current WordPress setup, contact us today.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name