CVE-2026-85984
miniOrange OTP Login, Verification and SMS Notifications (WordPress) authentication bypass - mo_wp_login_intent=otp logs an unauthenticated caller in as any administrator
- Severity
- critical
- Affected product
- miniorange-otp-verification
- Affected versions
- miniorange-otp-verification ≤ 5.5.5
- Fixed in
- miniorange-otp-verification 5.5.6
- Added to NewScan
- 2026-09-27
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints miniorange-otp-verification from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-27 (/daily-cve). CVSS 9.8. mo_by_pass_login() has no password-intent guard on the skip_pass_fallback branch: an unauthenticated POST carrying mo_wp_login_intent=otp makes administrator role membership alone sufficient, so mo_get_user() skips wp_authenticate_username_password() and resolves a WP_User from a username lookup - a known username and an empty password are the whole attack, with no password or OTP checked. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - the same generic per-slug join the other WordPress rows in this pack use, no new code. THE SLUG IS VERIFIED, NOT INFERRED: api.wordpress.org/plugins/info/1.0/miniorange-otp-verification.json answers with 'miniOrange OTP Login, Verification and SMS Notifications' at version 5.5.6, which both confirms the directory name the readme join needs AND independently confirms the fix release (the advisory only says 'up to, and including, 5.5.5'). NOT the same plugin as the existing `miniorange-2-factor-authentication` key - the 2026-09-27 triage line tagged this CVE with that tech tag and it is wrong; same vendor, different slug, different codebase. Version-match only, and note the row is deliberately WIDER than the exploit: the bypass additionally requires four plugin options to be enabled together (WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, Admin OTP Bypass), none of which is observable from outside, so the finding reports a vulnerable version rather than a proven bypass - confirming it in-band means logging into a stranger's site as an administrator.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →