Description
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The miniOrange 2FA WordPress plugin, prior to version 6.2.7, fails to bind the newly configured second factor during the pre‑login challenge to the target user's existing authentication factors. An attacker who knows the user’s password can rebind that user’s second factor to an attacker‑controlled destination, complete the challenge, and assuming full control of the account.

Affected Systems

WordPress sites running the miniOrange 2FA plugin dated before 6.2.7 are affected. The vulnerability applies to any deployment where the plugin is enabled for user authentication.

Risk and Exploitability

The attack requires only knowledge of a user’s password and an ability to initiate a login. Because the plugin does not enforce proper binding of the second factor, the attacker can hijack the account without further privilege escalation. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the potential for full credential compromise yields a high risk profile. Attackers can leverage this to compromise administrative accounts and potentially gain broad site access.

Generated by OpenCVE AI on August 5, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the miniOrange 2FA plugin to version 6.2.7 or later.
  • Reconfigure the plugin to ensure that any second‑factor binding is tied exclusively to the currently authenticated user.
  • Implement log monitoring to detect anomalous second‑factor rebinding attempts and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 5, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
Title miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:12.569Z

Reserved: 2026-07-17T09:01:50.500Z

Link: CVE-2026-16036

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses