PatchSiren

miniOrange CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL miniOrange CVE published 2026-08-25

CVE-2026-77998

CVE-2026-77998 is a critical unauthenticated authentication bypass vulnerability in several Joomla extensions, including miniOrange SAML SSO, SAML SP Single Sign On – Login with ADFS, and SAML SP Single Sign On – SAML SSO login with Google Apps. The vulnerability arises from a flawed boolean check in the mo_saml_validate_signature() function, which incorrectly treats an error return value from PHP's opens [truncated]

HIGH miniOrange CVE published 2026-08-06

CVE-2026-16619

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login. This allows an attacker who already knows a user's password to guess the one-time code without limit and take over the account. The vulnerability affects WordPress sites using the miniOrange 2FA plug [truncated]

CRITICAL miniOrange CVE published 2026-08-06

CVE-2026-65520

CVE-2026-65520 is an unauthenticated SQL injection vulnerability in the WP OAuth Server plugin for WordPress, affecting versions 6.2.0 or earlier. This critical vulnerability, with a CVSS score of 9.3, allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. The CVE record was published on 2026-08-06T15:17:15.607Z. Limited information is available about aff [truncated]

HIGH miniOrange CVE published 2026-08-05

CVE-2026-16036

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.

HIGH miniOrange CVE published 2026-07-31

CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

MEDIUM miniOrange CVE published 2026-07-27

CVE-2026-65561

A Contributor Cross Site Scripting (XSS) vulnerability exists in WordPress Social Login and Register plugin versions up to 7.8.0. This issue allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the plugin should apply updates to prevent XSS attacks. The [truncated]