SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12695

HIGH · CVSS 8.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The miniOrange 2FA WordPress plugin prior to version 6.2.6 is vulnerable as it fails to properly validate one-time passwords, allowing an unauthenticated attacker with knowledge of a victim's password to bypass two-factor authentication. This flaw can lead to unauthorized access to user accounts, including those of administrators, significantly compromising site security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-12695
Severity
HIGH
CVSS
8.1
EPSS
0.29%
WordPress

Original NVD Description

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.