VYPR

miniOrange Social Login and Register

by WordPress

CVEs (2)

  • CVE-2024-11087HigMar 8, 2025
    risk 0.53cvss 8.1epss 0.00

    The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social…

  • CVE-2026-14300HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.00

    The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers…