Critical Joomla and WordPress Flaws Exploited – Patch Now to Avoid Takeover

by The Creator | Jul 13, 2026

Two critical wordpress plugin vulnerability exploits are now active in the wild. Attackers are targeting Joomla iCagenda and Balbooa Forms extensions plus the miniOrange OAuth SSO plugin (CVE-2026-57807) to gain full website control, and CISA warns that patches must be applied or plugins disabled without delay.

Today's cyber news focuses on critical vulnerabilities affecting small businesses and timely security actions required. CISA warned that two Joomla extension flaws, in iCagenda and Balbooa Forms, are being actively exploited, allowing attackers to upload malicious files and potentially take over websites. A separate critical WordPress plugin vulnerability (CVE-2026-57807) in the miniOrange OAuth SSO plugin carries a 9.8 severity score and allows unauthenticated remote attackers to bypass authentication and gain full site control. With no official patch available, administrators must immediately disable the plugin.

On the innovation front, researchers introduced ScamBuster, an AI-driven system that engages phishing scammers with fake victim personas to gather intelligence on cybercriminal operations. However, the same AI capabilities are being weaponized, threat actors now use AI-generated PowerShell scripts to automate Active Directory reconnaissance, lowering the technical barrier for attacks.

In breach news, Lidl customers in the Netherlands, Belgium, and Germany were affected by a third-party IT provider breach that exposed names, email addresses, phone numbers, and dates of birth. Though passwords and payment information were not compromised, customers are urged to watch for targeted phishing attempts.

Small business owners should prioritize immediate patching or disabling of affected Joomla and WordPress plugins, monitor for unusual authentication activity, and train staff to recognize phishing attempts, especially those using recently stolen data.

What wordpress plugin vulnerability threats do SMBs face right now?

Three active exploits target small business websites. The Joomla iCagenda and Balbooa Forms extensions allow file uploads that lead to site takeover. The miniOrange OAuth SSO plugin carries a 9.8 severity score and bypasses authentication entirely, giving attackers full admin access. CISA confirms active exploitation. SMBs running WordPress or Joomla must immediately audit installed plugins, disable or uninstall iCagenda, Balbooa Forms, and miniOrange OAuth SSO, then apply vendor patches. Check your admin panel under Plugins today. Verify no unauthorized user accounts exist. Monitor login activity for suspicious authentication attempts over the next 30 days.

Key takeaways

  • Disable miniOrange OAuth SSO plugin immediately. No official patch exists yet. Full admin takeover is possible without authentication.
  • Update or remove Joomla iCagenda and Balbooa Forms extensions. Both are actively exploited for file upload and site control attacks.
  • Check user accounts and login logs. Attackers may have already created admin accounts. Require password resets for all staff.
  • Train staff on phishing attempts. Recent Lidl breach exposed customer data now being used for targeted scams against small business employees.

Frequently asked questions

What happens if I don't patch my WordPress or Joomla site?

Attackers gain full control of your website, install malware, steal customer data, deface your site, or use it to attack other businesses. Your site could be down for days during recovery. If your site takes customer payments, you may face PCI compliance violations and liability claims.

How do I know if my site is using the vulnerable plugins?

Log into your WordPress admin panel and go to Plugins. Search for iCagenda, Balbooa Forms, and miniOrange OAuth SSO. If they appear, disable and remove them. Contact your developer if you are unsure which plugins your site runs.

Should I be worried about the Lidl breach if I don't shop there?

Yes. The stolen data (names, emails, phone numbers, dates of birth) is now being used to send targeted phishing emails to small business employees. Train your team to verify sender addresses, avoid clicking links in unsolicited emails, and report suspicious messages to you immediately.

What is ScamBuster and does it affect my business?

ScamBuster is a security research tool that fights phishing by mimicking victims. It does not affect your business directly. However, the same AI techniques that power it are being used by attackers to automate attacks on Active Directory systems, making hacks easier to execute.

Sources

Keep reading