๐Ÿ” CVE Alert

CVE-2026-16035

UNKNOWN 0.0

miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.

Vendor unknown
Product miniorange 2fa
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown miniorange 2fa

Be the first to know when new unknown vulnerabilities affecting unknown miniorange 2fa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / miniOrange 2FA
0 < 6.2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/26217efe-b867-4bb9-ac7c-765fb796e2c1/

Credits

Revanth Hari Narayana Matte WPScan