CVE-2026-16619
Received Received - Intake

Brute Force Bypass in miniOrange 2FA WordPress Plugin

Vulnerability report for CVE-2026-16619, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
miniorange miniorange_2fa to 6.2.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The miniOrange 2FA WordPress plugin before version 6.2.8 has a flaw where it does not properly restrict the number of attempts for second-factor verification. Instead of tracking attempts per user account, it uses a client-supplied identifier that changes with each login. This allows an attacker who already knows a user's password to repeatedly guess the one-time code without being locked out, potentially gaining unauthorized access to the account.

Impact Analysis

If you use the affected miniOrange 2FA plugin, an attacker who knows your password could exploit this flaw to bypass two-factor authentication. They can repeatedly guess the one-time code until they succeed, gaining full control of your account. This could lead to data theft, unauthorized actions on your WordPress site, or further compromise of your systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations using the affected plugin may fail to meet security controls for access management, risking non-compliance and potential fines or penalties.

Mitigation Strategies

Update the miniOrange 2FA WordPress plugin to version 6.2.8 or later to fix the issue. If immediate update is not possible, consider disabling the plugin temporarily or implementing rate limiting on verification attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart