VYPR

miniOrange 2FA

by WordPress

CVEs (6)

  • CVE-2026-77770CriSep 10, 2026
    risk 0.65cvss 10.0epss 0.00

    The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can…

  • CVE-2026-12695HigJul 31, 2026
    risk 0.53cvss 8.1epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass…

  • CVE-2026-77771HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who…

  • CVE-2026-16619HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the…

  • CVE-2026-16036HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an…

  • CVE-2026-16035MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients…