The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mowploginintent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skippassfallback-enabled configuration branch of the mobypasslogin() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mowploginintent is submitted with the value otp, causing mogetuser() to skip wpauthenticateusernamepassword() and resolve a WPUser purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mowploginintent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.