CyberRota
← Ana sayfaya dön

CVE-2026-12695

UNKNOWN · CVSS N/A

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-31T07:16:23.747 · Çekilme zamanı: 2026-07-31T12:07:45.609152+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-12695
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.