PT-2026-99412 · WordPress · Miniorange Otp Login
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
miniOrange OTP Login, Verification and SMS Notifications versions prior to 5.5.6
Description
An authentication bypass exists when the
mo wp login intent parameter is used. The issue occurs within the mo by pass login() function, specifically in the skip pass fallback-enabled configuration branch, where a missing password-intent guard allows administrator role membership to be treated as sufficient authentication. When an unauthenticated user submits the mo wp login intent parameter with the value otp, the mo get user() function skips the wp authenticate username password() process and resolves a user based solely on a username lookup. This allows an attacker to log in as any administrator by providing a known username and an empty password. This behavior is conditional on the site administrator having enabled the WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass options.Recommendations
Update the plugin to a version newer than 5.5.5.
As a temporary mitigation, disable the Admin OTP Bypass option or the Login with Only OTP setting to prevent the authentication bypass.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Miniorange Otp Login