CVE-2026-16619: miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16619?
The severity of CVE-2026-16619 is high, with a CVSS score of 7.5.
How do I fix CVE-2026-16619?
Fix CVE-2026-16619 by updating the miniOrange 2FA WordPress plugin to version 6.2.8 or later.
What vulnerability does CVE-2026-16619 exploit?
CVE-2026-16619 exploits the unlimited attempts for second-factor verification in the miniOrange 2FA plugin.
Who is affected by CVE-2026-16619?
Users of miniOrange 2FA WordPress plugin versions prior to 6.2.8 are affected by CVE-2026-16619.
What are the potential consequences of CVE-2026-16619?
The potential consequences of CVE-2026-16619 include unauthorized access to user accounts through successful bypass of two-factor authentication.