PatchSiren cyber security CVE debrief
CVE-2026-65520 miniOrange CVE debrief
CVE-2026-65520 is an unauthenticated SQL injection vulnerability in the WP OAuth Server plugin for WordPress, affecting versions 6.2.0 or earlier. This critical vulnerability, with a CVSS score of 9.3, allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. The CVE record was published on 2026-08-06T15:17:15.607Z. Limited information is available about affected products and versions. To verify, defenders should review the official CVE record and assess their exposure. The vulnerability's critical severity indicates a high risk of exploitation. Organizations should prioritize patching to prevent potential SQL injection attacks. The WP OAuth Server plugin is used for authentication and authorization in WordPress environments. SQL injection attacks can result in unauthorized access to sensitive data or disruption of service. It is essential for administrators and security teams to take immediate action to protect their systems.
- Vendor
- miniOrange
- Product
- WP OAuth Server
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators and security teams responsible for WordPress installations using the WP OAuth Server plugin version 6.2.0 or earlier should prioritize patching to prevent potential SQL injection attacks. Additionally, operators and platforms using this plugin should review their exposure and take necessary actions.
Technical summary
CVE-2026-65520 is an unauthenticated SQL injection vulnerability in WP OAuth Server plugin version 6.2.0 or earlier. The vulnerability has a CVSS score of 9.3, indicating critical severity. This type of vulnerability allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise.
Defensive priority
Organizations using WP OAuth Server plugin version 6.2.0 or earlier should prioritize patching to prevent potential SQL injection attacks.
Recommended defensive actions
- Patch WP OAuth Server plugin to version greater than 6.2.0
- Inventory WP OAuth Server plugin versions in use
- Monitor for suspicious SQL queries
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates an unauthenticated SQL injection vulnerability in WP OAuth Server plugin version 6.2.0 or earlier. The CVSS score is 9.3, indicating critical severity. Limited information is available about affected products and versions. To verify, defenders should review the official CVE record and assess their exposure.
Official resources
-
CVE-2026-65520 CVE record
CVE.org
-
CVE-2026-65520 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:15.607Z and has not been modified since then.