CVE-2026-16619

miniOrange 2FA <= 6.2.7 - Two-Factor Authentication Bypass via Brute Force

2026-07-30 00:00
Farid Narimanov

Strategic Overview

Status
Patched in 6.2.8
Affected Version
<= 6.2.7
CVSS
3.1Low
Weakness type
CWE-307 · Improper Restriction of Excessive Authentication Attempts
CVE
CVE-2026-16619
View all miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) vulnerabilities

At a glance

CVE-2026-16619 is a low-severity Improper Restriction of Excessive Authentication Attempts vulnerability in the miniOrange 2FA WordPress plugin, affecting versions <= 6.2.7. It carries a CVSS score of 3.1 (reachable over the network). The issue is fixed in version 6.2.8; sites on affected versions should update now. Disclosed July 2026, reported by Farid Narimanov.

Vulnerability Overview

The miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 6.2.7. This is due to no restrictions on the number of 2FA code attempts that can be made. This makes it possible for unauthenticated attackers to brute force 2FA codes.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no interaction from a victim user.

CWE-307: Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Remediation

Update to version 6.2.8, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: miniOrange 2FA 6.2.8 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C