AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16619

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The miniOrange 2FA WordPress plugin prior to version 6.2.8 is vulnerable due to inadequate restrictions on the number of second-factor verification attempts, allowing attackers with a user's password to repeatedly guess the one-time code. This flaw can lead to account takeover, posing a significant risk to user accounts and sensitive data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-16619
Severity
HIGH
CVSS
7.5
EPSS
0.24%
WordPress

Original NVD Description

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.