CVE-2026-12695
Vulnerability Description
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
miniOrange 2FA
Discussion (0)
Add Comment
No comments yet. Be the first!