CVE-2026-77770
The miniOrange 2FA WordPress plugin has a critical flaw that lets anyone on the internet delete site options without logging in. This can lock administrators out of the dashboard or turn the plugin off entirely. The issue is fixed in newer releases of the plugin.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
WordPress sites using the miniOrange 2FA plugin, specifically versions before 6.3.1 and before 19.3.
Real-world impact
An attacker can delete any site option, potentially disabling the admin dashboard or the miniOrange 2FA plugin, effectively taking control of the site’s security settings.
Why this severity
The CVSS score of 10 reflects that the vulnerability requires no authentication, no user interaction, and gives an attacker full control over the site’s configuration, compromising confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the miniOrange 2FA WordPress plugin to version 6.3.1 or later.
- 02Verify the plugin is active and functioning after the upgrade.
NVD description
Timeline
- Sep 10, 2026 · 4d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.