# miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Two-Factor Authentication Bypass via Delay OTP Verification Setting

- **ID:** WPSEC-2026-0718
- **Plugin:** miniOrange OTP Login, Verification and SMS Notifications (`miniorange-otp-verification`), https://wordpress.org/plugins/miniorange-otp-verification/
- **Affected versions:** all versions before 5.5.8
- **Fixed in:** 5.5.8 (Update to 5.5.8 or later.)
- **Severity:** High 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/miniorange-otp-verification
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0718/

## Description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the 'Delay OTP Verification' login setting in all versions up to, and including, 5.5.7. This is due to the grace period being tracked only by a per-user 'last verified' timestamp that is not bound to the device or browser that completed OTP verification, and being applied unconditionally when the interval is negative. This makes it possible for unauthenticated attackers to skip OTP verification for a user who recently completed it, which needs only the target's username when 'login with OTP only' (passwordless) mode is enabled and the target's password otherwise, and to log in as that user.

## References

- https://wpsec.com/vuln/WPSEC-2026-0718/
- https://plugins.svn.wordpress.org/miniorange-otp-verification/tags/5.5.8/
- https://wordpress.org/plugins/miniorange-otp-verification/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0718/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
