Impact
The miniOrange 2FA WordPress plugin version 6.2.6 and earlier fails to verify that a user is permitted to request a one‑time‑password (OTP) and sends the generated OTP to the email address supplied by the attacker. This flaw, a missing authorization (CWE‑862), allows a low‑privileged user to cause OTP emails to be sent to arbitrary recipients, thereby leaking the OTP to untrusted parties and exhausting the site’s metered OTP quota, which in turn blocks legitimate users from obtaining the OTP required for second‑factor authentication.
Affected Systems
Vendors and products affected include the miniOrange 2FA WordPress plugin when its version is 6.2.6 or earlier. No specific product version list is available beyond the critical threshold of 6.2.7.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of < 1% suggests that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw can be exploited by any active WordPress user with access to the site’s backend or front‑end, as the plugin accepts HTTP requests to trigger the OTP send function. Because the attack does not require elevated privileges or complex setup, the risk of exploitation remains notable in environments where the plugin is installed and the user base is not tightly controlled. The vulnerability can be triggered via a straightforward web request to the plugin’s settings endpoint, making it a low‑barrier attack vector.
OpenCVE Enrichment