PT-2026-99412 · WordPress · Miniorange Otp Login

·

CVE-2026-85984

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions miniOrange OTP Login, Verification and SMS Notifications versions prior to 5.5.6
Description An authentication bypass exists when the mo wp login intent parameter is used. The issue occurs within the mo by pass login() function, specifically in the skip pass fallback-enabled configuration branch, where a missing password-intent guard allows administrator role membership to be treated as sufficient authentication. When an unauthenticated user submits the mo wp login intent parameter with the value otp, the mo get user() function skips the wp authenticate username password() process and resolves a user based solely on a username lookup. This allows an attacker to log in as any administrator by providing a known username and an empty password. This behavior is conditional on the site administrator having enabled the WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass options.
Recommendations Update the plugin to a version newer than 5.5.5. As a temporary mitigation, disable the Admin OTP Bypass option or the Login with Only OTP setting to prevent the authentication bypass.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85984

Affected Products

Miniorange Otp Login