CVE-2023-0812: Miniorange Active Directory Integration / LDAP Integration

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

Affected products

  • Miniorange Active Directory Integration / LDAP Integration: before 4.1.1 (fixed in 4.1.1)

Published 2023-05-15. Last modified 2026-06-17.