Email Verification Vulnerability in miniOrange Social Login Plugin for WordPress
CVE-2026-14300
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
Badges
What is CVE-2026-14300?
The miniOrange Social Login and Register plugin for WordPress allows attackers to exploit a flaw in the email verification process. Specifically, prior to version 7.8.0, the plugin does not associate the one-time code generated for the email verification feature with the intended user account. This flaw enables unauthorized users to gain access to any account, including those of administrators, by using a one-time code sent to an email they control and replaying it against another user's email address. This vulnerability requires the Profile Completion feature to be activated and the social login configuration to be set up, highlighting the importance of securing authentication processes.
Affected Version(s)
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) 0 < 7.8.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.