WordPress miniOrange Social Login and Register是WordPress基金会的一款集成社交登录与注册功能的CMS插件。 WordPress miniOrange Social Login and Register 7.8.0之前版本存在授权问题漏洞,该漏洞源于未能将可选电子邮件验证功能中使用的一次性代码绑定到为其发放的账户,导致未经验证攻击者能够通过请求其控制邮箱的代码并重放到受害者邮箱,从而获取任何账户(包括管理员)的有效会话。攻击需要启用个人资料完成功能并配置
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) | < 7.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) | 0 ~ 7.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11351 | ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosur | |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | |
| CVE-2026-13605 | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute | |
| CVE-2026-13423 | Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call | |
| CVE-2026-14234 | WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF | |
| CVE-2026-14224 | Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDO | |
| CVE-2026-13690 | UsersWP < 1.2.67 - Two-Factor Authentication Bypass | |
| CVE-2026-13692 | PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering |
No comments yet