← All CVEs NewScan detects
critical

CVE-2026-85984

miniOrange OTP Login, Verification and SMS Notifications (WordPress) authentication bypass - mo_wp_login_intent=otp logs an unauthenticated caller in as any administrator

Severity
critical
Affected product
miniorange-otp-verification
Affected versions
miniorange-otp-verification ≤ 5.5.5
Fixed in
miniorange-otp-verification 5.5.6
Added to NewScan
2026-09-27
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints miniorange-otp-verification from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-27 (/daily-cve). CVSS 9.8. mo_by_pass_login() has no password-intent guard on the skip_pass_fallback branch: an unauthenticated POST carrying mo_wp_login_intent=otp makes administrator role membership alone sufficient, so mo_get_user() skips wp_authenticate_username_password() and resolves a WP_User from a username lookup - a known username and an empty password are the whole attack, with no password or OTP checked. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - the same generic per-slug join the other WordPress rows in this pack use, no new code. THE SLUG IS VERIFIED, NOT INFERRED: api.wordpress.org/plugins/info/1.0/miniorange-otp-verification.json answers with 'miniOrange OTP Login, Verification and SMS Notifications' at version 5.5.6, which both confirms the directory name the readme join needs AND independently confirms the fix release (the advisory only says 'up to, and including, 5.5.5'). NOT the same plugin as the existing `miniorange-2-factor-authentication` key - the 2026-09-27 triage line tagged this CVE with that tech tag and it is wrong; same vendor, different slug, different codebase. Version-match only, and note the row is deliberately WIDER than the exploit: the bypass additionally requires four plugin options to be enabled together (WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, Admin OTP Bypass), none of which is observable from outside, so the finding reports a vulnerable version rather than a proven bypass - confirming it in-band means logging into a stranger's site as an administrator.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →