Impact
The vulnerability to make unlimited one‑time passcode guesses because the plugin does not scope its second‑, instead tying it to a client‑controlled identifier that can be changed at will. The flaw stems from improper authentication controls, a client‑controlled identifier that can be modified at will, and a secondary validation endpoint that applies no attempt limit; this reflects an improper authentication weakness (CWE-287).
Affected Systems
WordPress installations with miniOrange 2FA plugin versions earlier than 6.3.1 or earlier than 19.3 are affected. The product is the miniOrange 2FA (Free & Pro) WordPress plugin.
Risk and Exploitability
The vulnerability is exploitable by legitimate users who already possess a user's password and can submit malicious passcode guesses through standard login flows. Attackers need only supply a client‑controlled identifier to reset the counter, so the second‑factor lockout can be evaded entirely. The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1 % indicates a very low probability of exploitation, but the impact remains high because the second factor is effectively bypassed. The flaw is not listed in the CISA KEV catalog, yet it removes the intended security layer entirely, and the lack of a restrictor on the second validation endpoint means the flaw can be abused without any special network conditions.
OpenCVE Enrichment