This story first broke on July 9, 2026.

A popular WordPress login plugin has a flaw that lets a stranger take over an admin account with no password and no user interaction required.

What to Do

1. Check whether your site runs the miniOrange login or password recovery plugin.

2. If it does, remove it. There is currently no official fix available.

3. If you’re not sure what login or security plugins your site is running, that’s worth checking directly rather than assuming.

Why “No Fix Yet” Changes the Response

Most plugin vulnerabilities get resolved with an update. This one doesn’t have a patch available, which means updating isn’t currently an option. The flaw sits in the password recovery flow and can be triggered by anyone, without a password and without tricking a user into clicking anything. Until a fix ships, removing the plugin is the only way to close the door.

An admin account taken over this way gives an attacker the same access the site owner has, full control of content, users, and anything connected to the site. Having someone check what’s actually installed is the fastest way to know if this applies before it becomes a bigger problem.

Source: Cyber Security News