- Description
- The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mo_wp_login_intent is submitted with the value otp, causing mo_get_user() to skip wp_authenticate_username_password() and resolve a WP_User purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mo_wp_login_intent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-287
- Hype score
- Not currently trending
CVE-2026-85984 — WordPress miniOrange OTP (≤5.5.5) Unauth admin bypass: wp-login.php + mo_wp_login_intent=otp + empty password (misconfigured Admin OTP Bypass). CVSS 9.8 — patch 5.5.6+. 📖 https://t.co/L3m5petlbS #WordPress #CVE #CyberSecurity #PoC #InfoSec
@murrezsec
28 Sept 2026
128 Impressions
0 Retweets
3 Likes
0 Bookmarks
2 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-97163 CVE-2026-18143 CVE-2026-82901 CVE-2026-85984 CVE-2026-94132 ..🧵👇
@exploitgrid
27 Sept 2026
1906 Impressions
2 Retweets
22 Likes
9 Bookmarks
1 Reply
0 Quotes