WordPress in miniOrange – OAuth Single Sign On – SSO

Wordpress 588494 640

A serious security issue has been discovered in the miniOrange OAuth Single Sign-On (SSO) plugin for WordPress.

The flaw could allow someone on the internet to gain access to a website without knowing the correct username or password. In the worst cases, an attacker could take control of the affected website.

This issue affects all versions up to 38.5.8, and there is currently no official fix available from the plugin developer.

Who should be concerned?

  • Website owners: If your WordPress site uses the miniOrange OAuth Single Sign-On plugin, check whether you’re affected.
  • Everyone else: If you only visit websites and don’t manage one, this vulnerability does not put your personal device at risk.

What should website owners do?

Until an official update is released:

  • Check whether your website uses the miniOrange OAuth Single Sign-On plugin.
  • Monitor the plugin developer for security updates.
  • Consider temporarily disabling the plugin if your website can operate without it.
  • Watch your website for any unusual login activity.

Bottom Line

This is a serious vulnerability for websites using the affected plugin, but it is not something that can infect your computer or phone simply by browsing the web. If you don’t run a WordPress website with this plugin installed, you don’t need to take any action.

References

Scroll to Top