Executive brief
Various free Joomla plugins from miniOrange are vulnerable to unauthenticated removal of any installed extension due to missing authentication checks. An attacker on the network can delete critical plugins without logging in, disrupting site functionality and potentially making a Joomla installation inoperable.
Technical details
The vulnerability is an authentication bypass (CWE-306) in multiple free miniOrange Joomla plugins. A missing authentication check in the extension deinstallation function allows unauthenticated remote attackers to construct requests that trigger arbitrary extension removal. No special privileges, valid credentials, or user interaction are required; network access to the Joomla installation is sufficient. An attacker can systematically delete all installed extensions, rendering the site inoperable. Only free versions of miniOrange plugins are affected; paid versions likely contain the authentication controls.
Affected products
- miniOrange Joomla Extensions (free versions) free versions only
Timeline
- 2026-08-31: disclosed