plugin

Miniorange 2 Factor Authentication Vulnerabilities

12 known security issues reported for the Miniorange 2 Factor Authentication WordPress plugin. Most recent disclosed Jul 27, 2026.

4 high 8 medium

Running Miniorange 2 Factor Authentication on your site? Check whether your installed version is affected.

Scan your site free

miniOrange 2FA <= 6.2.6 - Missing Authorization

medium

The miniOrange 2FA plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.2.6
Fixed in:
6.2.7
Disclosed:
Jul 27, 2026

CVE-2026-16035 on NVD →

miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) < 6.2.6 - Two-Factor Authentication Bypass

medium

The miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to two-factor authentication bypass in all versions up to 6.2.6 (exclusive). This makes it possible for unauthenticated attackers to bypass two-factor authentication.

CVSS:
5.3
Affected:
up to 6.2.6
Fixed in:
6.2.6
Disclosed:
Jul 15, 2026

CVE-2026-12695 on NVD →

miniOrange's Google Authenticator <= 6.1.1 - Missing Authorization

medium

The miniOrange 2-factor Authentication (2FA with SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and a...

CVSS:
4.3
Affected:
up to 6.1.1
Fixed in:
6.1.2
Disclosed:
Aug 23, 2025

CVE-2025-54745 on NVD →

miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change

high

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.

CVSS:
7.5
Affected:
up to 5.6.5
Fixed in:
5.6.6
Disclosed:
Apr 19, 2023

CVE-2022-4943 on NVD →

miniOrange's Google Authenticator <= 5.6.1 - Sensitive Data Exposure of Multifactor Backup Codes

high

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.6.1 via functions such as 'mo_wpns_get_progress' and 'mo2f_use_backup_codes'. This can allow attackers to extract sensitive data about multifactor authentication backup codes, and info...

CVSS:
7.5
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Nov 23, 2022

CVE-2022-44589 on NVD →

miniOrange's Google Authenticator <= 5.6.1 - Cross-Site Request Forgery to Malware Scan Termination

high

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on the mo_wpns_stop_scan function. This makes it possible for unauthenticated attackers to terminate malware scans, via for...

CVSS:
8.8
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Nov 1, 2022

miniOrange's Google Authenticator <= 5.6.1 - Missing Authorization to Plugin Settings Change

medium

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the plugin'...

CVSS:
5.4
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Oct 31, 2022

CVE-2022-42461 on NVD →

miniOrange's Google Authenticator <= 5.5.82 - Missing Authorization

medium

miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an the mo_wpns_malware_redirect function in versions up to, and including, 5.5.82. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to initiat...

CVSS:
6.3
Affected:
up to 5.5.82
Fixed in:
5.6.0
Disclosed:
Sep 16, 2022

miniOrange's Google Authenticator <= 5.5.7 - Reflected Cross-Site Scripting

medium

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.7. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
up to 5.5.7
Fixed in:
5.5.75
Disclosed:
Jun 27, 2022

miniOrange's Google Authenticator <= 5.5.5 - Authenticated (Admin+) Cross-Site Scripting

medium

The miniOrange's Google Authenticator plugin for WordPress vulnerable to Stored Cross-Site Scripting via the ‘Add Referer’ field in versions up to, and including, 5.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities to inje...

CVSS:
5.5
Affected:
up to 5.5.5
Fixed in:
5.5.6
Disclosed:
Jun 6, 2022

CVE-2022-1321 on NVD →

miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion

high

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

CVSS:
8.1
Affected:
up to 5.4.52
Fixed in:
5.5
Disclosed:
Feb 28, 2022

CVE-2022-0229 on NVD →

miniOrange's Google Authenticator <= 5.4.39 - Cross-Site Scripting

medium

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user’ parameter in versions up to, and including, 5.4.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 5.4.39
Fixed in:
5.4.40
Disclosed:
Aug 10, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database