CyberRota Analysis
AI-GeneratedThe miniOrange 2FA plugin for WordPress versions prior to 6.2.7 is vulnerable due to inadequate restrictions on who can initiate the sending of one-time passcodes (OTPs), allowing low-privileged users to send OTPs to any email address. This can lead to denial of service for legitimate users by exhausting the site's OTP quota, preventing them from receiving necessary authentication codes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.