Back to CVE List

CVE-2026-12695

Vulnerability Description

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
miniOrange 2FA

External References

Discussion (0)

Add Comment

No comments yet. Be the first!