CVE-2026-16619
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | miniOrange 2FA | 0 < 6.2.8 | affected |
Weaknesses
- CWE-307 Improper Restriction of Excessive Authentication Attempts
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.