Email Verification Vulnerability in miniOrange Social Login Plugin for WordPress
CVE-2026-14300

Currently unrated

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-14300?

The miniOrange Social Login and Register plugin for WordPress allows attackers to exploit a flaw in the email verification process. Specifically, prior to version 7.8.0, the plugin does not associate the one-time code generated for the email verification feature with the intended user account. This flaw enables unauthorized users to gain access to any account, including those of administrators, by using a one-time code sent to an email they control and replaying it against another user's email address. This vulnerability requires the Profile Completion feature to be activated and the social login configuration to be set up, highlighting the importance of securing authentication processes.

Affected Version(s)

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) 0 < 7.8.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lyris Vale
WPScan
.