Back

HIGH

miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts

Published Aug 6, 2026

Description

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 6, 2026
Updated Aug 7, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Aug 7, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Aug 6, 2026
Updated Aug 7, 2026
Exploited since n/a
EUVD-2026-54204