PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65520 miniOrange CVE debrief

CVE-2026-65520 is an unauthenticated SQL injection vulnerability in the WP OAuth Server plugin for WordPress, affecting versions 6.2.0 or earlier. This critical vulnerability, with a CVSS score of 9.3, allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. The CVE record was published on 2026-08-06T15:17:15.607Z. Limited information is available about affected products and versions. To verify, defenders should review the official CVE record and assess their exposure. The vulnerability's critical severity indicates a high risk of exploitation. Organizations should prioritize patching to prevent potential SQL injection attacks. The WP OAuth Server plugin is used for authentication and authorization in WordPress environments. SQL injection attacks can result in unauthorized access to sensitive data or disruption of service. It is essential for administrators and security teams to take immediate action to protect their systems.

Vendor
miniOrange
Product
WP OAuth Server
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Administrators and security teams responsible for WordPress installations using the WP OAuth Server plugin version 6.2.0 or earlier should prioritize patching to prevent potential SQL injection attacks. Additionally, operators and platforms using this plugin should review their exposure and take necessary actions.

Technical summary

CVE-2026-65520 is an unauthenticated SQL injection vulnerability in WP OAuth Server plugin version 6.2.0 or earlier. The vulnerability has a CVSS score of 9.3, indicating critical severity. This type of vulnerability allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise.

Defensive priority

Organizations using WP OAuth Server plugin version 6.2.0 or earlier should prioritize patching to prevent potential SQL injection attacks.

Recommended defensive actions

  • Patch WP OAuth Server plugin to version greater than 6.2.0
  • Inventory WP OAuth Server plugin versions in use
  • Monitor for suspicious SQL queries
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record indicates an unauthenticated SQL injection vulnerability in WP OAuth Server plugin version 6.2.0 or earlier. The CVSS score is 9.3, indicating critical severity. Limited information is available about affected products and versions. To verify, defenders should review the official CVE record and assess their exposure.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:15.607Z and has not been modified since then.