miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 10epss 0.2%
from disclosure to weapon3 days
Published on NVDSep 10
1st PoC+3d
exploitation probability
0.2%top 84% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Affected products
Unknown · miniOrange 2FApublic PoCs found — 2
githubgithub.com/cflowsec/CVE-2026-77770★ 1cve_referencewpscan.com/vulnerability/68bc7294-1ee6-44a9-9995-3b23b921f750/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.