Impact
The miniOrange 2FA WordPress plugin gives an attacker who already knows a user’s password the ability to bypass the second‑factor authentication by repeatedly guessing the one‑time code without any restriction. Because the plugin tracks verification attempts using a client‑supplied identifier that is reissued on each login, the attempt counter is never enforced. When the attacker eventually discovers a valid code, the attacker can log in with full access to the account’s data and any associated administrative capabilities. This failure to enforce authentication bounds is a security weakness classified under CWE‑307.
Affected Systems
This flaw affects the miniOrange 2FA plugin for WordPress versions prior to 6.2.8. All installations of the plugin that have not been upgraded to version 6.2.8 or later are vulnerable. The plugin is commonly used on sites that rely on secondary authentication for site administrators and other privileged users.
Risk and Exploitability
The CVSS score of 7.5 indicates a high level of severity, meaning a successful exploit can result in full account takeover. The EPSS score is reported as less than 1%, implying a low probability of exploitation at the moment of analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers who have already compromised a user’s password can exploit the unlimited attempts to guess the one‑time code and gain unauthorized access to the account without additional authentication.
OpenCVE Enrichment