Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miniorange
Miniorange miniorange 2fa Wordpress Wordpress wordpress |
|
| Vendors & Products |
Miniorange
Miniorange miniorange 2fa Wordpress Wordpress wordpress |
Fri, 07 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-703 |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account. | |
| Title | miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-06T17:17:16.824Z
Reserved: 2026-07-22T14:45:41.884Z
Link: CVE-2026-16619
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T09:00:05Z