SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77770

CRITICAL · CVSS 10 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The miniOrange 2FA WordPress plugin versions prior to 6.3.1 and 19.3 are vulnerable to unauthorized deletion of site options due to insufficient validation of transaction requests. This flaw allows any unauthenticated visitor to delete critical options, potentially locking administrators out of the dashboard or disabling essential security features. WordPress site administrators using these plugin versions should prioritize immediate updates to mitigate the risk of unauthorized access and disruption.

CVE
CVE-2026-77770
Severity
CRITICAL
CVSS
10
EPSS
0.24%
WordPress

Original NVD Description

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.