miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Two-Factor Authentication Bypass via Delay OTP Verification Setting

High 7.4 CWE-287Fixed in 5.5.8
ID
WPSEC-2026-0718
Plugin
miniOrange OTP Login, Verification and SMS Notifications (miniorange-otp-verification)
Affected
all versions before 5.5.8
Remediation
Update to 5.5.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
miniOrange OTP Login, Verification and SMS Notifications on WPSec AttackSurface
Fix released
Published

Description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the 'Delay OTP Verification' login setting in all versions up to, and including, 5.5.7. This is due to the grace period being tracked only by a per-user 'last verified' timestamp that is not bound to the device or browser that completed OTP verification, and being applied unconditionally when the interval is negative. This makes it possible for unauthenticated attackers to skip OTP verification for a user who recently completed it, which needs only the target's username when 'login with OTP only' (passwordless) mode is enabled and the target's password otherwise, and to log in as that user.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0