CVE-2026-77770 PUBLISHED

miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator

Assigner: WPScan
Reserved: 21.08.2026 Published: 10.09.2026 Updated: 10.09.2026

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.

Product Status

Vendor Unknown
Product miniOrange 2FA
Versions Default: unaffected
  • affected from 5.3.24 to 6.3.1 (excl.)
Vendor Unknown
Product miniOrange 2FA
Versions Default: unaffected
  • affected from 18.0 to 19.3 (excl.)

Credits

  • Osman Hussein finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE