WordPress Plugin Vulnerabilities

miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout

Description

The plugin does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
pervinzahidli
Submitter
Pervin Zahidli
Verified
Yes

Timeline

Publicly Published
2026-09-08 (about 2 days ago)
Added
2026-09-08 (about 1 day ago)
Last Updated
2026-09-09 (about 8 hours ago)

Other