CyberRota Analysis
AI-GeneratedThe miniOrange 2FA WordPress plugin versions prior to 6.3.1 and 19.3 are vulnerable to unauthorized deletion of site options due to insufficient validation of transaction requests. This flaw allows any unauthenticated visitor to delete critical options, potentially locking administrators out of the dashboard or disabling essential security features. WordPress site administrators using these plugin versions should prioritize immediate updates to mitigate the risk of unauthorized access and disruption.
Original NVD Description
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.