miniOrange A.I CyberSecurity Scoring
miniOrange
Company Information
Website:https://www.miniorange.com/
Employees number:575
Number of followers:19,698
NAICS:5112
Industry Type:Software Development
Homepage:miniorange.com
miniOrange Risk Score (AI oriented)
Between 750 and 799
miniOrangeSoftware Development
Updated:
13/07/2026
13/07/2026
753/1000
Fair
Baa
miniOrange Global Score (TPRM)
xxxx
miniOrangeSoftware Development
Score locked

miniOrangeFair
Current Score
753Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
755
Vulnerability
09 Jul 2026 • miniOrange
miniOrange: Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
Critical WordPress OAuth Plugin Flaw Exposes Millions of Sites to Full Takeover
753
CRITICAL-2
MIN1783945821
Critical WordPress OAuth Plugin Flaw Exposes Millions of Sites to Full Takeover
A severe security vulnerability in the miniOrange OAuth Single Sign-On (SSO) plugin for WordPress has left millions of websites vulnerable to unauthenticated remote takeover. Tracked as CVE-2026-57807 with a CVSS score of 9.8, the flaw was disclosed by Patchstack on July 9, 2026, and classified under OWASP A7: Identification and Authentication Failures.
The issue stems from a Broken Authentication weakness (CWE-288), specifically exploiting the plugin’s password recovery mechanism via an alternate authentication pathway. Attackers can bypass login controls without prior access, authentication, or user interaction, making exploitation trivial and low-complexity. All versions of the plugin up to and including 38.5.8 are affected.
Successful exploitation allows attackers to impersonate any WordPress user, including administrators, leading to full site compromise. Potential consequences include malicious content injection, data exfiltration, backdoor installation, and lateral movement within the hosting environment.
Patchstack warns the flaw is highly likely to be exploited in mass campaigns, targeting websites regardless of size or traffic. While no official patch has been released by miniOrange, Patchstack has issued a virtual patch to block attacks until a fix is available.
Security researcher Kim Dvash reported the vulnerability on June 6, 2026, with the NVD publishing the CVE on July 10, 2026. Administrators are advised to deactivate and remove the plugin from exposed WordPress installations or restrict access to login and recovery endpoints via WAF rules or IP allowlisting as a temporary mitigation. Updates should be applied immediately upon release.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
755
MAY 2026
755
APRIL 2026
755
MARCH 2026
755
FEBRUARY 2026
755
JANUARY 2026
755
DECEMBER 2025
755
NOVEMBER 2025
755
OCTOBER 2025
755
SEPTEMBER 2025
755
AUGUST 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for miniOrange ??
What was miniOrange's A.I Rankiteo Cyber Score in June 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in May 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in April 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in March 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in February 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in January 2026 ??
What was miniOrange's A.I Rankiteo Cyber Score in December 2025 ??
What was miniOrange's A.I Rankiteo Cyber Score in November 2025 ??
What was miniOrange's A.I Rankiteo Cyber Score in October 2025 ??
What was miniOrange's A.I Rankiteo Cyber Score in September 2025 ??
What was miniOrange's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on miniOrange's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with miniOrange ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view miniOrange's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?