Impact
The miniOrange 2FA WordPress plugin, prior to version 6.2.7, fails to bind the newly configured second factor during the pre‑login challenge to the target user's existing authentication factors. An attacker who knows the user’s password can rebind that user’s second factor to an attacker‑controlled destination, complete the challenge, and assuming full control of the account.
Affected Systems
WordPress sites running the miniOrange 2FA plugin dated before 6.2.7 are affected. The vulnerability applies to any deployment where the plugin is enabled for user authentication.
Risk and Exploitability
The attack requires only knowledge of a user’s password and an ability to initiate a login. Because the plugin does not enforce proper binding of the second factor, the attacker can hijack the account without further privilege escalation. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the potential for full credential compromise yields a high risk profile. Attackers can leverage this to compromise administrative accounts and potentially gain broad site access.
OpenCVE Enrichment