Sploitus

CVE-2026-77771

1 known exploit for CVE-2026-77771

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.

CVSS 3.1
7.5 HIGH
EPSS
0.1% (3th percentile)
Weakness
CWE-287
NVD status
Deferred
Published
2026-09-10
CVE-2026-77771 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-77771

Proof-of-concept code and exploit modules indexed by Sploitus