CVE-2026-12761Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST parameter without verifying that the email belongs to the identity returned by the OAuth provider, combined with send_otp_token() returning the SHA-512(customer_key || otp) transaction hash to the client where the OTP space is only 99,000 values (wp_rand(1000, 99999)) and the customer_key is a static option (empty on unregistered installs). This makes it possible for unauthenticated attackers to trigger an OTP email to an arbitrary admin's address, crack the OTP offline from the leaked hash in under a second, and submit the cracked OTP to mo_openid_social_login_validate_otp(), which logs the attacker in as the user whose email was supplied — granting full administrator access.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-07-13)
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-12: 1Mentions · 2026-07-13: 3PoC Mentioned / Linked · 2026-07-13: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 307-1007-1107-1207-13
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-101
Patch1
2026-07-111
Disclosure1
2026-07-121
Disclosure1
2026-07-133
Disclosure2Patch1
Full discourse6 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-57807 & CVE-2026-12761: Two vulnerable WordPress plugins by miniOrange, 9.8 rating both 🔥 There are two authentication bypass vulnerabilities disclosed in miniOrange plugins: OAuth Single Sign On - SSO & Social Login and Register (Discord, Google, Twitter, LinkedIn). These flaws might allow a malicious actor to gain admin access to the website. 👉 https://nt.ls/M4c8B

    Post summary

    The tweet announces two authentication bypass vulnerabilities (CVE‑2026‑57807 and CVE‑2026‑12761) in miniOrange WordPress plugins, potentially allowing admin access, with no evidence of exploitation, PoC, or patching details.

    0501121.9K
    7.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-12761 - Critical Authentication Bypass in miniOrange #WordPress plugin. Unvalidated email field allows account takeover. #CVSS 9.8. No patch available. Disable plugin immediately. #CVEAlert #DevSecops #devops #git #gitlab #github #infosec #sysadmin #linux #developers

    Post summary

    The tweet announces a critical authentication bypass in miniOrange's WordPress plugin (CVE‑2026‑12761) with a CVSS score of 9.8, warns of no available patch, and urges users to disable the plugin immediately.

    1000074
    978 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-12761 — CVSS 9.8/10 ██████████ The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/I6MKN1ez0Y

    Post summary

    A brief alert about the critical CVE‑2026‑12761 affecting the miniOrange plugin, highlighting the need for immediate patching, with no PoC, exploit details, or active exploitation evidence included.

    10000159
    65 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-12761 (CVSS 9.8) miniOrange Social Login plugin for WordPress ≤7.7.0 vulnerable to authentication bypass → full admin takeover. Unauthenticated attackers can crack OTP & gain admin access. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/5djXEBqqpb

    Post summary

    The post warns that CVE‑2026‑12761 in the miniOrange Social Login WordPress plugin allows unauthenticated attackers to bypass authentication and gain full admin control, urging users to apply a patch immediately.

    0000041
    71 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: WordPress Auth Bypass Cluster — CVSS 9.8 + 8.8 CVE-2026-12761: miniOrange Social Login — unauthenticated admin takeover via OTP bypass CVE-2026-14262: Simple JWT Login — subscriber-to-admin privilege escalation → http://threataft.com/articles/wordpress-miniorange-social-login-simple-jwt-login-auth-bypass #cybersecurity #WordPress

    Post summary

    The post announces two critical WordPress authentication bypass CVEs with CVSS scores and directs readers to an external link for further details, focusing on disclosure rather than exploitation or patching.

    0000066
    34 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-12761 (CVSS 9.8): miniOrange Social Login plugin for WordPress vulnerable to authentication bypass and account takeover in versions up to 7. Verify and update sites using it. https://nvd.nist.gov/vuln/det… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/bbtFDQH1V5

    Post summary

    The tweet announces a CVE affecting miniOrange Social Login, details authentication bypass and account takeover vulnerabilities, and urges sites to verify and apply available updates, linking to the NVD advisory.

    0000052
    89 followersView on X

Explore more