{
 "id": "WPSEC-2026-0718",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0718/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0718/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0718/index.md",
 "title": "miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Two-Factor Authentication Bypass via Delay OTP Verification Setting",
 "description": "The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the 'Delay OTP Verification' login setting in all versions up to, and including, 5.5.7. This is due to the grace period being tracked only by a per-user 'last verified' timestamp that is not bound to the device or browser that completed OTP verification, and being applied unconditionally when the interval is negative. This makes it possible for unauthenticated attackers to skip OTP verification for a user who recently completed it, which needs only the target's username when 'login with OTP only' (passwordless) mode is enabled and the target's password otherwise, and to log in as that user.",
 "plugin": {
  "slug": "miniorange-otp-verification",
  "name": "miniOrange OTP Login, Verification and SMS Notifications",
  "full_name": "miniOrange OTP Login, Verification and SMS Notifications",
  "wordpress_org": "https://wordpress.org/plugins/miniorange-otp-verification/",
  "advisories_url": "https://wpsec.com/vuln/plugin/miniorange-otp-verification/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/miniorange-otp-verification"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.5.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.5.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.5.8",
 "remediation": "Update to 5.5.8 or later.",
 "fix_released": "2026-10-08T06:42:24+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:32.774028+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0718/",
  "https://plugins.svn.wordpress.org/miniorange-otp-verification/tags/5.5.8/",
  "https://wordpress.org/plugins/miniorange-otp-verification/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/miniorange-otp-verification",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}