Authentication Bypass
3 records27.3%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 11 vulnerability records associated with miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon, published between 2022 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 1 | |
| 2023 | 5 | |
| 2025 | 3 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 18.2% |
| High | 4 | 36.4% |
| Medium | 5 | 45.5% |
First: 2023. Latest: 2026.
First: 2022. Latest: 2023.
First: 2023. Latest: 2026.
First: 2025. Latest: 2025.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
7.8.17.8.07.7.0200.3.107.6.77.6.57.5.157.6.07.6.17.5.13Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-7.8.0 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | July 24, 2026 | 7.8.1 | Medium |
*-7.7.0 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow | July 10, 2026 | 7.8.0 | Critical |
*-7.7.0 | Social Login and Register <= 7.7.0 - Authenticated (Administrator+) Local File Inclusion | September 28, 2025 | Not supplied | Medium |
*-7.6.10 | WordPress Social Login and Register <= 7.6.10 - Unauthenticated Local File Inclusion | May 21, 2025 | 7.7.0 | High |
*-200.3.9 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass | March 7, 2025 | 200.3.10 | High |
*-7.6.6 | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.6 - Authenticated (Subscriber+) Privilege Escalation | November 9, 2023 | 7.6.7 | High |
*-7.6.4 | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass | June 28, 2023 | 7.6.5 | Critical |
*-7.5.14 | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Cross-Site Request Forgery | February 15, 2023 | 7.5.15 | High |
*-7.5.14 | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 15, 2023 | 7.6.0 | Medium |
*-7.6.0 | WordPress Social Login and Register <= 7.6.0 - Missing Authorization to Unauthenticated Arbitrary Content Deletion | February 13, 2023 | 7.6.1 | Medium |
7.5.12 | WordPress Social Login and Register <=7.5.12 - Missing Authorization to Plugin Settings Update | September 23, 2022 | 7.5.13 | Medium |
Selected source records
Published: July 24, 2026
Published: July 10, 2026
Published: September 28, 2025
Published: May 21, 2025
Published: March 7, 2025
Published: November 9, 2023
Published: June 28, 2023
Published: February 15, 2023
Published: June 28, 2023
Published: July 10, 2026
Published: November 9, 2023
Published: February 15, 2023
Published: May 21, 2025
Published: March 7, 2025
Published: September 28, 2025
Published: September 23, 2022
Published: September 28, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.