CVE-2026-16036: miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
miniOrange 2FA WordPress pluginto a version that resolves this vulnerability.Fixed in 6.2.7 - Operational
After upgrading miniOrange 2FA to 6.2.7, review affected WordPress accounts for any changes to bound second-factor destinations performed via password-only second-factor rebinding (and re-enroll second factor as needed).
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-16036?
The risk level of CVE-2026-16036 is rated at 80.
What does CVE-2026-16036 exploit?
CVE-2026-16036 exploits a weakness in the miniOrange 2FA WordPress plugin that allows 2FA bypass via password-only second-factor rebinding.
How can I mitigate CVE-2026-16036?
To mitigate CVE-2026-16036, update the miniOrange 2FA plugin to version 6.2.7 or later.
Who is affected by CVE-2026-16036?
Users of the miniOrange 2FA WordPress plugin prior to version 6.2.7 are affected by CVE-2026-16036.
What action should I take if I am using an older version of miniOrange 2FA?
If you are using an older version of miniOrange 2FA, you should upgrade to version 6.2.7 or higher immediately to prevent potential exploitation.