miniOrange 2FA <= 6.2.6 - Missing Authorization
medium
The miniOrange 2FA plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 6.2.6
- Fixed in:
- 6.2.7
- Disclosed:
- Jul 27, 2026
CVE-2026-16035 on NVD →
miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) < 6.2.6 - Two-Factor Authentication Bypass
medium
The miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to two-factor authentication bypass in all versions up to 6.2.6 (exclusive). This makes it possible for unauthenticated attackers to bypass two-factor authentication.
- CVSS:
- 5.3
- Affected:
- up to 6.2.6
- Fixed in:
- 6.2.6
- Disclosed:
- Jul 15, 2026
CVE-2026-12695 on NVD →
miniOrange's Google Authenticator <= 6.1.1 - Missing Authorization
medium
The miniOrange 2-factor Authentication (2FA with SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 6.1.1
- Fixed in:
- 6.1.2
- Disclosed:
- Aug 23, 2025
CVE-2025-54745 on NVD →
miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change
high
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
- CVSS:
- 7.5
- Affected:
- up to 5.6.5
- Fixed in:
- 5.6.6
- Disclosed:
- Apr 19, 2023
CVE-2022-4943 on NVD →
miniOrange's Google Authenticator <= 5.6.1 - Sensitive Data Exposure of Multifactor Backup Codes
high
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.6.1 via functions such as 'mo_wpns_get_progress' and 'mo2f_use_backup_codes'. This can allow attackers to extract sensitive data about multifactor authentication backup codes, and info...
- CVSS:
- 7.5
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Nov 23, 2022
CVE-2022-44589 on NVD →
miniOrange's Google Authenticator <= 5.6.1 - Cross-Site Request Forgery to Malware Scan Termination
high
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on the mo_wpns_stop_scan function. This makes it possible for unauthenticated attackers to terminate malware scans, via for...
- CVSS:
- 8.8
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Nov 1, 2022
miniOrange's Google Authenticator <= 5.6.1 - Missing Authorization to Plugin Settings Change
medium
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the plugin'...
- CVSS:
- 5.4
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Oct 31, 2022
CVE-2022-42461 on NVD →
miniOrange's Google Authenticator <= 5.5.82 - Missing Authorization
medium
miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an the mo_wpns_malware_redirect function in versions up to, and including, 5.5.82. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to initiat...
- CVSS:
- 6.3
- Affected:
- up to 5.5.82
- Fixed in:
- 5.6.0
- Disclosed:
- Sep 16, 2022
miniOrange's Google Authenticator <= 5.5.7 - Reflected Cross-Site Scripting
medium
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.7. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.75
- Disclosed:
- Jun 27, 2022
miniOrange's Google Authenticator <= 5.5.5 - Authenticated (Admin+) Cross-Site Scripting
medium
The miniOrange's Google Authenticator plugin for WordPress vulnerable to Stored Cross-Site Scripting via the ‘Add Referer’ field in versions up to, and including, 5.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities to inje...
- CVSS:
- 5.5
- Affected:
- up to 5.5.5
- Fixed in:
- 5.5.6
- Disclosed:
- Jun 6, 2022
CVE-2022-1321 on NVD →
miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion
high
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
- CVSS:
- 8.1
- Affected:
- up to 5.4.52
- Fixed in:
- 5.5
- Disclosed:
- Feb 28, 2022
CVE-2022-0229 on NVD →
miniOrange's Google Authenticator <= 5.4.39 - Cross-Site Scripting
medium
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user’ parameter in versions up to, and including, 5.4.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 5.4.39
- Fixed in:
- 5.4.40
- Disclosed:
- Aug 10, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database