Description
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass of Two‑Factor Authentication
Action: Patch Now
AI Analysis

Impact

The vulnerability to make unlimited one‑time passcode guesses because the plugin does not scope its second‑, instead tying it to a client‑controlled identifier that can be changed at will. The flaw stems from improper authentication controls, a client‑controlled identifier that can be modified at will, and a secondary validation endpoint that applies no attempt limit; this reflects an improper authentication weakness (CWE-287).

Affected Systems

WordPress installations with miniOrange 2FA plugin versions earlier than 6.3.1 or earlier than 19.3 are affected. The product is the miniOrange 2FA (Free & Pro) WordPress plugin.

Risk and Exploitability

The vulnerability is exploitable by legitimate users who already possess a user's password and can submit malicious passcode guesses through standard login flows. Attackers need only supply a client‑controlled identifier to reset the counter, so the second‑factor lockout can be evaded entirely. The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1 % indicates a very low probability of exploitation, but the impact remains high because the second factor is effectively bypassed. The flaw is not listed in the CISA KEV catalog, yet it removes the intended security layer entirely, and the lack of a restrictor on the second validation endpoint means the flaw can be abused without any special network conditions.

Generated by OpenCVE AI on September 10, 2026 at 17:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the miniOrange 2FA WordPress plugin to version 6.3.1 or later (or 19.3 or later if using the pro edition, disable the second validation endpoint or otherwise restrict its use through the plugin’s configuration to prevent unlimited OTP attempts.
  • Implement additional monitoring of OTP request patterns for signs of brute‑force activity and enforce stricter rate limits on OTP generation and delivery.
  • Review and tighten any custom authentication rules or network access controls that might allow bypassing the 2FA flow, ensuring that only trusted clients can reach the second validation endpoint.

Generated by OpenCVE AI on September 10, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CWE-307

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
Title miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-10T13:11:50.760Z

Reserved: 2026-08-21T10:58:08.233Z

Link: CVE-2026-77771

cve-icon Vulnrichment

Updated: 2026-09-10T13:06:13.443Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T07:17:03.047

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-77771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:15:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-307

    Improper Restriction of Excessive Authentication Attempts