CVE-2026-77771
miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
| Vendor | unknown |
| Product | miniorange 2fa |
| Published | Sep 10, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown miniorange 2fa
Be the first to know when new high vulnerabilities affecting unknown miniorange 2fa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / miniOrange 2FA
6.2.8 < 6.3.1
Unknown / miniOrange 2FA
18.0 < 19.3
References
Credits
pervinzahidli WPScan