miniOrange 2FA WordPress 插件在 6.3.1 之前的版本以及 19.3 之前的版本存在一个缺陷:该插件未将第二因子验证的尝试次数限制与正在受攻击的账户关联,而是将其绑定到由客户端提供且可随时更改的标识符上。这使得已经知道受害者密码的攻击者能够进行无限制的一次性密码(OTP)猜测,从而绕过第二因子认证。此外,第二个验证端点完全没有设置尝试次数限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | miniOrange 2FA | 6.2.8 ~ 6.3.1 | - |
|
| Unknown | miniOrange 2FA | 18.0 ~ 19.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82925 | Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature | |
| CVE-2026-81431 | Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un | |
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em | |
| CVE-2026-78361 | zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio | |
| CVE-2026-19840 | Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet