CVE-2026-16035
Received Received - Intake

Unauthorized OTP Send in miniOrange 2FA WordPress Plugin

Vulnerability report for CVE-2026-16035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
miniorange miniorange_2fa to 6.2.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The miniOrange 2FA WordPress plugin before version 6.2.7 has a flaw where any low-privileged user can send one-time-passcode (OTP) emails to arbitrary recipients. This is because the plugin does not restrict who can trigger OTP sends or bind the OTP to the enrolling user's address. Attackers can exploit this to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.

Detection Guidance

Check if your WordPress site uses the miniOrange 2FA plugin version before 6.2.7. Inspect user roles for unauthorized OTP requests or unusual email activity. Review server logs for excessive OTP email generation attempts.

Impact Analysis

This vulnerability allows attackers to disrupt second-factor authentication for legitimate users by sending excessive OTP requests. This could lock users out of their accounts, preventing access to critical services. Additionally, it may lead to denial-of-service conditions if the OTP allowance is exhausted.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to send OTP emails to arbitrary recipients, which may lead to unauthorized access to sensitive data. Exhausting the site's metered OTP allowance could prevent legitimate users from receiving second-factor codes, compromising secure authentication and data protection measures required by these regulations.

Mitigation Strategies

Update the miniOrange 2FA WordPress plugin to version 6.2.7 or later to address the OTP configuration flaw.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart