miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Two-Factor Authentication Bypass via Delay OTP Verification Setting
- ID
- WPSEC-2026-0718
- Plugin
- miniOrange OTP Login, Verification and SMS Notifications (miniorange-otp-verification)
- Affected
- all versions before 5.5.8
- Remediation
- Update to 5.5.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- miniOrange OTP Login, Verification and SMS Notifications on WPSec AttackSurface
- Fix released
- Published
Description
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the 'Delay OTP Verification' login setting in all versions up to, and including, 5.5.7. This is due to the grace period being tracked only by a per-user 'last verified' timestamp that is not bound to the device or browser that completed OTP verification, and being applied unconditionally when the interval is negative. This makes it possible for unauthenticated attackers to skip OTP verification for a user who recently completed it, which needs only the target's username when 'login with OTP only' (passwordless) mode is enabled and the target's password otherwise, and to log in as that user.
References
- https://wpsec.com/vuln/WPSEC-2026-0718/
- https://plugins.svn.wordpress.org/miniorange-otp-verification/tags/5.5.8/
- https://wordpress.org/plugins/miniorange-otp-verification/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS