CVE-2026-12695 PUBLISHED

miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret

Assigner: WPScan
Reserved: 19.06.2026 Published: 31.07.2026 Updated: 31.07.2026

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

Product Status

Vendor Unknown
Product miniOrange 2FA
Versions Default: unaffected
  • affected from 0 to 6.2.6 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE