The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Thu, 10 Sep 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-640 |
Thu, 10 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site. | |
| Title | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-10T06:00:06.054Z
Updated: 2026-09-10T13:12:06.700Z
Reserved: 2026-08-21T10:57:53.664Z
Link: CVE-2026-77770
Updated: 2026-09-10T13:06:41.939Z
Status : Deferred
Published: 2026-09-10T07:17:02.943
Modified: 2026-09-10T15:13:07.090
Link: CVE-2026-77770
No data.