miniOrange Social Login and Register Pro Addon Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass has been identified in the miniOrange Social Login and Register Pro Addon for WordPress, in all versions through 200.3.9. The issue arises from inadequate verification of users associated with social login tokens, enabling unauthenticated attackers to log in as any existing user, including administrators. This exploitation is possible if the attacker knows the username and the user lacks an existing account with the service providing the token.

Impact

Exploitation of this vulnerability allows for unauthorized login as any existing user, potentially including users with administrative privileges.

Remediation

Users are advised to update the miniOrange Social Login and Register Pro Addon to version 200.3.10 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.