
🚨 CRITICAL: WordPress Auth Bypass Cluster — CVSS 9.8 + 8.8 CVE-2026-12761: miniOrange Social Login — unauthenticated admin takeover via OTP bypass CVE-2026-14262: Simple JWT Login — subscriber-to-admin privilege escalation → http://threataft.com/articles/wordpress-miniorange-social-login-simple-jwt-login-auth-bypass #cybersecurity #WordPress
Post summary
The text announces a cluster of critical WordPress authentication bypass vulnerabilities (CVE-2026-12761 and CVE-2026-14262), providing brief technical details and a link to an article, but no PoC, exploit code, or evidence of active exploitation.


