
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68974 is a PHP Local File Inclusion (LFI) vulnerability in the miniOrange WordPress Social Login and Register plugin (miniorange-login-openid). It affects all versions of the plugin through 7.7.0 and was published on December 30, 2025, with the vulnerability originally reported on August 29, 2025, and disclosed by Patchstack on September 28, 2025. The vulnerability carries a CVSS v3.1 base score of 6.6 (Medium/High), though exploitation requires high privileges (Patchstack).
The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program — PHP Remote File Inclusion), manifesting as a Local File Inclusion flaw. An attacker with high-level privileges (e.g., Administrator) can manipulate file path parameters used in PHP include/require statements within the plugin, causing the server to include arbitrary local files and render their contents. The attack vector is network-based with high attack complexity and requires no user interaction, but does require high privileges to trigger (Patchstack).
Successful exploitation allows an attacker to include and expose arbitrary local files on the WordPress server, potentially revealing sensitive credentials such as database connection strings stored in configuration files (e.g., wp-config.php). Depending on server configuration, this could escalate to full database compromise or arbitrary PHP code execution if attacker-controlled content can be included. The vulnerability has high impact on confidentiality, integrity, and availability of the affected system (Patchstack).
No official patch was available at the time of disclosure; the plugin versions through 7.7.0 remain vulnerable. Administrators should update the miniOrange WordPress Social Login and Register plugin to any version newer than 7.7.0 as soon as a patched release becomes available. As an interim measure, consider disabling the plugin entirely until a fix is released, and deploy a Web Application Firewall (WAF) to monitor and block suspicious file inclusion attempts. Review server logs for anomalous file access patterns related to the plugin (Patchstack).
The vulnerability received brief social media attention shortly after disclosure, with mentions on Mastodon and Bluesky via TheHackerWire accounts. No significant vendor statements or in-depth researcher commentary have been published beyond the Patchstack advisory. Community sentiment appears muted given the high privilege requirement and low exploitation probability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."