What is CVE-2026-14300?
The miniOrange Social Login and Register WordPress plugin before version 7.8.0 fails to bind the one-time code from its email verification feature to the relevant account. This flaw allows unauthenticated attackers to obtain a valid session. Users should immediately update to version 7.8.0 or later.
Azərbaycanca: miniOrange Social Login and Register WordPress plagininin 7.8.0 əvvəlki versiyalarında e-poçt doğrulama funksiyasındakı birdəfəlik kod hesaba bağlanmır. Bu boşluq autentifikasiya olunmamış hücumçulara etibarlı sessiya əldə etməyə imkan verir. Plagindən istifadə edənlər dərhal 7.8.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: miniOrange
FAQ2
Which versions of the miniOrange plugin are affected by CVE-2026-14300?
All versions of the miniOrange Social Login and Register plugin before version 7.8.0 are affected. Users should immediately update to version 7.8.0 or later.
What does the CVE-2026-14300 flaw allow an unauthenticated attacker to do?
This flaw allows unauthenticated attackers to obtain a valid session through the one-time code in the email verification feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.