Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

WordPress SSO Plugin Flaw: No Patch, Disable It Now

A widely-used WordPress plugin that lets website visitors log in using their Google, Microsoft or Facebook account has been found to contain a critical security flaw, and at the time of writing there is no patch available from the vendor. If your website uses the miniOrange WordPress OAuth Single Sign-On plugin, the only safe action right now is to deactivate and remove it.

What has happened?

Security researcher Kim Dvash identified a critical authentication bypass vulnerability, tracked as CVE-2026-57807, in the miniOrange WordPress OAuth Single Sign-On (SSO OAuth Client) plugin. The flaw was reported on 6 June 2026 and published to the Patchstack vulnerability database on 9 July 2026. Patchstack is one of the main registries that tracks security weaknesses specifically in WordPress plugins and themes.

The vulnerability carries a CVSS score of 9.8 out of 10. CVSS (Common Vulnerability Scoring System) is the standard scale security professionals use to rate severity: anything above 9.0 is considered Critical.

The bug lives in the plugin’s password recovery mechanism. Rather than keeping login paths controlled and verified, the code leaves open an alternative route that skips identity checks entirely. An attacker who knows this route can authenticate as any user on the site – including an administrator – without providing a password, without having an account, and without any action from the site owner or its visitors.

Because the attack requires no login credentials and no user interaction, it is trivial to automate. Criminals routinely scan the entire internet for sites running known vulnerable plugin versions, so any site with the affected plugin installed is a potential target – not just large or high-profile ones.

What is SSO and why does it matter here?

Single Sign-On (SSO) is a technology that lets users log into a website using credentials from another service they already have, such as a Google or Microsoft account. Many business websites use SSO plugins to make login simpler for staff or members, or to connect their website to their company’s Microsoft 365 system. The miniOrange plugin is a popular choice for this, which is why the number of affected sites is so large.

Is there a patch?

No. At the time of writing, the vendor has not released an updated version of the plugin. There is also no safe configuration workaround that allows you to keep the plugin active. Until an official fix is confirmed in the WordPress Plugin Directory, deactivating and removing the plugin is the only reliable way to close the exposure.

What this means for your business

An attacker who gains administrator access to a WordPress site can cause serious damage. They can read or steal contact form submissions and customer data, install hidden code that serves malware to visitors, redirect pages to fraudulent websites, deface the site, or lock the legitimate owner out entirely. For businesses that rely on their website to generate enquiries or accept bookings, the consequences – both financial and reputational – can far outlast the original incident.

This vulnerability follows a pattern we see regularly: third-party plugins extend what WordPress can do, but they also introduce risk that WordPress’s own security updates cannot address. The core WordPress software receives updates frequently, but plugin vendors maintain their own code separately, and flaws can remain undiscovered in widely-used plugins for months.

What you should do right now

  • Deactivate and remove the plugin. Log in to your WordPress dashboard, go to Plugins, find miniOrange WordPress OAuth Single Sign-On, and deactivate and delete it. If you are unsure who manages your website, contact your web developer or IT provider immediately.
  • Check your administrator accounts. In your WordPress dashboard, go to Users and filter by the Administrator role. Look for any accounts you do not recognise. Remove them and change all administrator passwords as a precaution.
  • Run a security scan. Use a reputable WordPress security tool such as Wordfence to scan for any unexpected code or files. Attackers who gain admin access often install a back door so they can return even after the vulnerable plugin is removed.
  • Review recent activity. If your site uses an activity or audit log plugin, check for any unusual login events over the past few weeks – particularly any successful administrator logins that you cannot account for.
  • Watch for a vendor patch. Monitor the miniOrange plugin page in the WordPress Plugin Directory. If a patched version is confirmed, you can then decide whether to re-enable it.

How we can help

System Force IT manages WordPress websites for a number of our clients, and we have already reviewed those sites for this plugin. Where clients are affected, we are contacting them directly.

If your website is managed by someone else – or you are unsure who looks after it – our IT security team can carry out a review. Keeping on top of plugin vulnerabilities is exactly the kind of proactive monitoring we build into the managed IT services we provide to businesses across Gloucestershire and the wider UK, so that you do not have to track it yourself.

If you have not yet considered Cyber Essentials certification, incidents like this one illustrate why its patch management and malware protection controls matter: they are specifically designed to ensure vulnerabilities like CVE-2026-57807 are caught and closed before they cause a problem.

To have your WordPress site reviewed or to discuss your broader IT security posture, get in touch or call 01452 701355 for a no-obligation conversation.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name