CVE-2026-85984: miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mowploginintent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skippassfallback-enabled configuration branch of the mobypasslogin() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mowploginintent is submitted with the value otp, causing mogetuser() to skip wpauthenticateusernamepassword() and resolve a WPUser purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mowploginintent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to exploitation?
Only sites running plugin version 5.5.5 or earlier with all four options enabled are exposed: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass. The vulnerable path is specifically the skip_pass_fallback-enabled configuration branch.
What does an attacker need to bypass authentication?
An attacker needs the username of an existing administrator account. They can submit that username with an empty password and mo_wp_login_intent set to otp; no valid password or OTP is required.
What can be done if the plugin cannot be patched immediately?
Disable at least one of the required options, particularly Admin OTP Bypass or the combination that enables Login with Only OTP and username/password login. This prevents the stated vulnerable configuration from being present.
How can administrators determine whether their site is currently vulnerable?
Check whether the installed plugin version is 5.5.5 or earlier, then review its settings for the simultaneous enablement of WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass. A site is affected only when all of these conditions are met.