WordPress SSO Plugin Flaw: No Patch, Disable It Now
A critical unpatched vulnerability (CVE-2026-57807, CVSS 9.8) in the miniOrange WordPress OAuth SSO plugin lets attackers log in as administrator with no password. Here is what site owners need to do immediately.
September 6, 2026
Security Updates & Threats