CVE-2024-11087

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username and the user does not have an already-existing account for the service returning the token.


We have discovered 136 live websites that are affected by CVE-2024-11087.

Run a Free Instant Scan




Affected Software

Product  Miniorange Login Openid
Category Wordpress Plugins
Vulnerable Domains136 live websites (65% of Miniorange Login Openid install base)
Vulnerable Versions
  • from 0 through 7.6.9
Vulnerable Versions Count12 versions ( 86% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Mar 8, 2025
  • Updated - Mar 11, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-11087
United States46 websites



Singapore14 websites
Russia11 websites
Germany8 websites
Netherlands5 websites
Cyprus5 websites
Denmark4 websites
Italy3 websites
Canada3 websites
Poland3 websites

Website Distribution by TLD

Number of websites using CVE-2024-11087
.com69 websites
.ru7 websites
.nl4 websites
.dk3 websites
.it3 websites
.info3 websites
.ca2 websites
.co.uk2 websites
.com.au2 websites
.cz2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11087

Top websites that are affected by CVE-2024-11087. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.****.edu United States***,***
*************.com United States***,***
*****************.com United States***,***
*******.**********************.com United States***,***
******.se Sweden*,***,***
*************.com United States*,***,***
*****.ua Ukraine*,***,***
*******.sg Singapore*,***,***
*********.co United States*,***,***
*************.com United States*,***,***
See full domain list

FAQ

CVE-2024-11087 is Improper Authentication in Miniorange Login Openid
A total of 136 websites have been identified as vulnerable to CVE-2024-11087, based on global website indexing conducted by WebTechSurvey.
The Miniorange Login Openid is affected by the CVE-2024-11087 vulnerability.
Miniorange Login Openid versions up to and including 7.6.9 are vulnerable to CVE-2024-11087.