← Back

Miniorange

miniorange

56 CVEs • 27 products

Products (27)

Click to collapse
Toggle
Saml
saml
Social Login
social_login

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Miniorange
1Active Directory Integration / Ldap Integration
Apr 23, 2025
Oct 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never remove...Show more
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.Show less
1Miniorange
1Active Directory Integration / Ldap Integration
Apr 8, 2026
Sep 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This...Show more
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.Show less
1Miniorange
1Staff / Employee Business Directory For Active Directory
Apr 8, 2026
Sep 27, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP serv...Show more
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.Show less
1Miniorange
1Prevent Files / Folders Access
Apr 22, 2025
Sep 25, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
1Miniorange
1Oauth Single Sign On
Apr 28, 2026
Jul 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
1Miniorange
1Web3 Crypto Wallet Login & Nft Token Gating
Apr 8, 2026
Jun 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_...Show more
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.Show less
1Miniorange
1Active Directory Integration / Ldap Integration
Apr 8, 2026
Jun 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This...Show more
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to extract potentially sensitive information from the LDAP directory.Show less
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Apr 8, 2026
Jun 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on...Show more
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.Show less
1Miniorange
1Active Directory Integration / Ldap Integration
Apr 8, 2026
Jun 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to mi...Show more
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to cause resource exhaustion via a forged request granted they can trick an administrator into performing an action such as clicking on a link.Show less
1Miniorange
1Active Directory Integration / Ldap Integration
Apr 8, 2026
Jun 9, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user suppli...Show more
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Nov 21, 2024
May 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
1Miniorange
1Active Directory Integration / Ldap Integration
Jan 24, 2025
May 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Nov 21, 2024
Apr 25, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
1Miniorange
1Oauth Single Sign On
Feb 19, 2025
Mar 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
1Miniorange
1Oauth Single Sign On
Feb 19, 2025
Mar 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise...Show more
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attackShow less
1Miniorange
1Saml Sp Single Sign On
Mar 28, 2025
Jan 30, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not va...Show more
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.Show less
1Miniorange
1Ldap Integration With Active Directory And Openldap
Apr 3, 2025
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this...Show more
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.Show less
1Miniorange
1Login With Cognito
Apr 10, 2025
Jan 2, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the u...Show more
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Miniorange
1Wordpress Rest Api Authentication
Nov 21, 2024
Nov 18, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
1Miniorange
1Google Authenticator
Nov 21, 2024
Nov 18, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.