CVE-2026-59545 HIGH

CVE-2026-59545: WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability

Vendor Miniorange
Product miniOrange Discord Integration
Weakness CWE-288
Published July 23, 2026
Last update July 23, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

Explanation of Vulnerability in Simple Terms

02Summary

miniOrange Discord Integration versions up to 2.2.4 contain an authentication bypass vulnerability. An attacker can exploit this flaw to gain unauthorized access to the integration without valid credentials. The vulnerability requires specific network conditions but does not require user interaction. Affected sites should update immediately.

What an attacker can do

03Attacker Capabilities

Bypass authentication and gain unauthorized access to the Discord integration without valid credentials.

Potential impact on your site

04Site Impact

Attackers can access Discord integration features and potentially read or modify connected Discord data without authorization.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable integration; no user interaction or authentication required.

Key dates

06Disclosure timeline

July 23, 2026 CVE published

Related vulnerabilities

08Related CVE