Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77771— miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout

Quick assessment

Affected
Unknown miniOrange 2FA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

miniOrange 2FA WordPress 插件在 6.3.1 之前的版本以及 19.3 之前的版本存在一个缺陷:该插件未将第二因子验证的尝试次数限制与正在受攻击的账户关联,而是将其绑定到由客户端提供且可随时更改的标识符上。这使得已经知道受害者密码的攻击者能够进行无限制的一次性密码(OTP)猜测,从而绕过第二因子认证。此外,第二个验证端点完全没有设置尝试次数限制。

AI Predicted 7.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77771

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
Source: CVE Program / CVE List V5
Vulnerability Description
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown miniOrange 2FA 6.2.8 ~ 6.3.1 -
Unknown miniOrange 2FA 18.0 ~ 19.3 -

II. Public POCs for CVE-2026-77771

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77771

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77771 (1)

Same Patch Batch · Unknown · 2026-09-10 · 8 CVEs total

CVE-2026-82925 Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
CVE-2026-81431 Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un
CVE-2026-77770 miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em
CVE-2026-78361 zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio
CVE-2026-19840 Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions
CVE-2026-19436 Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v
CVE-2026-19439 Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus

IV. Related Vulnerabilities

V. Comments for CVE-2026-77771

No comments yet


Leave a comment