Miniorange develops a focused suite of authentication and identity-management plugins, primarily for Active Directory and LDAP integration alongside multi-factor authentication and single-sign-on capabilities, that secure access to widely deployed business applications. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability that reflects the high-value nature of authentication-layer flaws. The exposure recurs across its identity-platform product line through weakness classes including cross-site scripting, cross-site request forgery, authentication bypass, and missing authentication for critical functions—gaps that are characteristic of complex identity-federation and session-management implementations. Because these products sit in the authentication path of many enterprise systems, flaws in this vendor's offerings can provide broad lateral access; defenders should prioritize this vendor's updates for identity and access-control components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniorange over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2982CRITICAL The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. Th | Jun 29, 2023 | 9.8 | 67 | NO | YES |
CVE-2023-5003HIGH The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfo | Oct 16, 2023 | 7.5 | 46 | NO | YES |
CVE-2026-5343HIGH Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.
This issue affects SAML SSO - Service Provide | May 28, 2026 | 7.4 | 31 | NO | NO |
CVE-2022-34858CRITICAL Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress. | Aug 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-11087CRITICAL The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inclu | Mar 8, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-34149CRITICAL Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. | Aug 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-6036CRITICAL The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and ' | Feb 12, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-3249CRITICAL The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect auth | Jun 30, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-9862CRITICAL The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugi | Oct 17, 2024 | 9.8 | 28 | NO | NO |
CVE-2022-45073HIGH Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress. | Nov 18, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniorange.
Media articles that mention a CVE ID that affects a product developed by Miniorange — matched by CVE ID, not by vendor name.