Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-703 |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account. | |
| Title | miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-06T17:17:16.824Z
Reserved: 2026-07-22T14:45:41.884Z
Link: CVE-2026-16619
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T23:45:03Z
-
CWE-703
Improper Check or Handling of Exceptional Conditions