The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
CVE-2026-77771
NONE
EPSS 0.13%
Updated Sep 10, 2026
WordPress
CVE Details
CVE ID
CVE-2026-77771
Published Date
Sep 10, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.13%
Likelihood of exploitation in next 30 days
Percentile:
3.1th percentile (higher than 3.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory