Security readout for executives and security teams
Plain-English summary
This critical WordPress plugin flaw may allow an internet-based attacker to bypass authentication without credentials or user interaction. If successful, the published severity indicates possible loss of data confidentiality, integrity, and availability. The available sources do not explain the precise failure mechanism or confirm exploitation.
Executive priority
Treat as an immediate investigation and remediation priority for internet-facing WordPress sites using the affected plugin. Promptly establish inventory, business dependency, and authoritative upgrade guidance. Escalate incident review if logs show unexplained authentication or privilege activity.
Technical view
CVE-2026-28008 is an unauthenticated broken-authentication issue, classified as CWE-290, affecting OAuth Single Sign On – SSO (OAuth Client) through version 7.0.0. CVSS 3.1 rates it 9.8: network-accessible, low complexity, no privileges, no user interaction, unchanged scope, and high impact across confidentiality, integrity, and availability.
Likely exposure
Potential exposure is limited to WordPress sites running the named miniOrange plugin at version 7.0.0 or earlier. Risk is greatest where the plugin participates in externally reachable authentication. The structured affected-version data is inconsistent, listing versions as unavailable and defaulting to unaffected, so administrators should verify applicability with the vendor.
Exploitation context
The source bundle does not report active exploitation, and the CVE is not identified as being in CISA KEV. Its network-accessible, unauthenticated characteristics make it potentially attractive, but no public exploit status or attack mechanics are established by the supplied evidence.
Researcher notes
Public detail is sparse. The record supplies CWE-290 and a severe CVSS vector but no root cause, affected code path, prerequisites beyond network access, fixed release, or exploitation evidence. The affected-product metadata also conflicts with the title and description, warranting vendor confirmation before declaring a specific deployment vulnerable or remediated.
Mitigation direction
Inventory WordPress sites for the named plugin and record installed versions.
Check miniOrange and Patchstack guidance for a confirmed fixed version or mitigation.
Disable or remove affected versions where operationally acceptable until authoritative remediation is available.
Restrict administrative and authentication exposure where feasible without disrupting required access.
Preserve relevant authentication logs before making changes.
Validation and detection
Confirm whether the plugin is installed, enabled, and version 7.0.0 or earlier.
Identify which public WordPress authentication flows depend on the plugin.
Review authentication logs for unexplained logins, privilege changes, or newly created accounts.
Verify any replacement version against authoritative vendor or Patchstack guidance.
Retest legitimate OAuth sign-in and access controls after remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-290: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.