Description
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The miniOrange 2FA WordPress plugin, prior to version 6.2.7, fails to bind the newly configured second factor during the pre‑login challenge to the target user's existing authentication factors. An attacker who knows the user’s password can rebind that user’s second factor to an attacker‑controlled destination, complete the challenge, and assuming full control of the account.

Affected Systems

WordPress sites running the miniOrange 2FA plugin dated before 6.2.7 are affected. The vulnerability applies to any deployment where the plugin is enabled for user authentication.

Risk and Exploitability

The attack requires only knowledge of a user’s password and an ability to initiate a login. Because the plugin does not enforce proper binding of the second factor, the attacker can hijack the account without further privilege escalation. The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the potential for full credential compromise yields a high risk profile. Attackers can leverage this to compromise administrative accounts and potentially gain broad site access.

Generated by OpenCVE AI on August 5, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the miniOrange 2FA plugin to version 6.2.7 or later.
  • Reconfigure the plugin to ensure that any second‑factor binding is tied exclusively to the currently authenticated user.
  • Implement log monitoring to detect anomalous second‑factor rebinding attempts and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 5, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange miniorange 2fa
Wordpress
Wordpress wordpress
Vendors & Products Miniorange
Miniorange miniorange 2fa
Wordpress
Wordpress wordpress

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
Title miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
References

Subscriptions

Miniorange Miniorange 2fa
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T15:17:06.672Z

Reserved: 2026-07-17T09:01:50.500Z

Link: CVE-2026-16036

cve-icon Vulnrichment

Updated: 2026-08-05T15:17:02.597Z

cve-icon NVD

Status : Received

Published: 2026-08-05T07:16:35.350

Modified: 2026-08-05T16:16:51.743

Link: CVE-2026-16036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:30:16Z

Weaknesses