Description
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
Published: 2026-09-10
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the miniOrange 2FA WordPress plugin versions before 6.3.1 for the Free edition and before 19.3 for the Pro edition. It allows any unauthenticated user to delete site options because the plugin does not validate the transaction before performing the delete operation. The lack of authorization control permits arbitrary removal of configuration settings, or deactivate the plugin, effectively causing a denial of service to site management.

Affected Systems

Affected systems include all WordPress sites that have the miniOrange 2FA plugin installed, both Free and Pro versions, running a version lower than 6.3.1 or 19.3 respectively. Administrators managing CMS installations should verify the plugin version in use and confirm that the update has been applied.

Risk and Exploitability

The CVSS score of 10.0 indicates a critical severity, but the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the KEV. The exploit requires no privileged access; a simple unauthenticated HTTP request to the plugin’s option deletion endpoint can delete arbitrary site options. Because the attacker can act via the website or through innocuous links, the risk of exploitation is high given the severity, despite the realistic score. Immediate patching is recommended.

Generated by OpenCVE AI on September 10, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update miniOrange version 6.3.1 or newer for the Free edition or 19.3 or newer for the Pro edition, deactivate the miniOrange 2FA plugin to prevent deletion operations.
  • Monitor the WordPress options table for unexpected deletions and review logs for abnormal activity.
  • Restrict HTTP traffic to the option deletion endpoint by whitelisting only authenticated IP ranges or blocking it entirely if the feature is not required.

Generated by OpenCVE AI on September 10, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-640

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-640

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
Title miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-10T13:12:06.700Z

Reserved: 2026-08-21T10:57:53.664Z

Link: CVE-2026-77770

cve-icon Vulnrichment

Updated: 2026-09-10T13:06:41.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T07:17:02.943

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-77770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:07Z

Weaknesses