CVE-2026-77771
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.1% (3th percentile)
- Weakness
- CWE-287
- NVD status
- Deferred
- Published
- 2026-09-10
CVE-2026-77771 at NVD
1 known exploit for CVE-2026-77771
Proof-of-concept code and exploit modules indexed by Sploitus