CVE-2026-16035: miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
miniOrange 2FA (WordPress plugin)to a version that resolves this vulnerability.Fixed in 6.2.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16035?
CVE-2026-16035 has a risk rating of 38.
How do I fix CVE-2026-16035?
To fix CVE-2026-16035, update the miniOrange 2FA WordPress plugin to version 6.2.7 or later.
What does CVE-2026-16035 affect?
CVE-2026-16035 affects the miniOrange 2FA WordPress plugin versions prior to 6.2.7.
What is the impact of CVE-2026-16035?
The impact of CVE-2026-16035 allows a low-privileged user to send one-time-passcode emails to arbitrary recipients.
Who is vulnerable to CVE-2026-16035?
Any WordPress site using versions of the miniOrange 2FA plugin prior to 6.2.7 is vulnerable to CVE-2026-16035.