AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-16035

UNKNOWN · CVSS N/A EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The miniOrange 2FA plugin for WordPress versions prior to 6.2.7 is vulnerable due to inadequate restrictions on who can initiate the sending of one-time passcodes (OTPs), allowing low-privileged users to send OTPs to any email address. This can lead to denial of service for legitimate users by exhausting the site's OTP quota, preventing them from receiving necessary authentication codes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16035
Severity
UNKNOWN
CVSS
N/A
EPSS
0.13%
WordPress

Original NVD Description

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.