Impact
The vulnerability resides in the miniOrange 2FA WordPress plugin versions before 6.3.1 for the Free edition and before 19.3 for the Pro edition. It allows any unauthenticated user to delete site options because the plugin does not validate the transaction before performing the delete operation. The lack of authorization control permits arbitrary removal of configuration settings, or deactivate the plugin, effectively causing a denial of service to site management.
Affected Systems
Affected systems include all WordPress sites that have the miniOrange 2FA plugin installed, both Free and Pro versions, running a version lower than 6.3.1 or 19.3 respectively. Administrators managing CMS installations should verify the plugin version in use and confirm that the update has been applied.
Risk and Exploitability
The CVSS score of 10.0 indicates a critical severity, but the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the KEV. The exploit requires no privileged access; a simple unauthenticated HTTP request to the plugin’s option deletion endpoint can delete arbitrary site options. Because the attacker can act via the website or through innocuous links, the risk of exploitation is high given the severity, despite the realistic score. Immediate patching is recommended.
OpenCVE Enrichment