CVE-2026-85984: miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter

Published Sep 26, 2026
·
Updated

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mowploginintent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skippassfallback-enabled configuration branch of the mobypasslogin() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mowploginintent is submitted with the value otp, causing mogetuser() to skip wpauthenticateusernamepassword() and resolve a WPUser purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mowploginintent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.

Affected Software

1 affected component
miniOrange OTP Login, Verification and SMS Notifications<=5.5.5

Event History

Sep 26, 2026
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Only sites running plugin version 5.5.5 or earlier with all four options enabled are exposed: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass. The vulnerable path is specifically the skip_pass_fallback-enabled configuration branch.

2

What does an attacker need to bypass authentication?

An attacker needs the username of an existing administrator account. They can submit that username with an empty password and mo_wp_login_intent set to otp; no valid password or OTP is required.

3

What can be done if the plugin cannot be patched immediately?

Disable at least one of the required options, particularly Admin OTP Bypass or the combination that enables Login with Only OTP and username/password login. This prevents the stated vulnerable configuration from being present.

4

How can administrators determine whether their site is currently vulnerable?

Check whether the installed plugin version is 5.5.5 or earlier, then review its settings for the simultaneous enablement of WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass. A site is affected only when all of these conditions are met.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203