ConicPlex

Start Your Project

A laptop glowing WordPress blue on a desk beside a broken keycard and an open padlock, symbolizing a WordPress plugin access-control vulnerability

On this Page

miniOrange 2FA Plugin Patches a Maximum-Severity Option-Deletion Flaw (CVE-2026-77770)

miniOrange 2FA patched CVE-2026-77770, a CVSS 10.0 flaw letting anyone delete WordPress options and lock out admins or disable 2FA. Update to 6.3.1 or 19.3.

Aftab Memon

September 12, 2026

The miniOrange 2FA plugin, installed on more than 10,000 WordPress sites to add two-factor login protection, shipped a fix on September 7, 2026 for a maximum-severity flaw that let anyone, logged in or not, delete arbitrary WordPress options on the site. Tracked as CVE-2026-77770 and assigned a CVSS score of 10.0, the bug sat in versions before 6.3.1 of the free edition and before 19.3 of the Pro edition, according to NVD’s entry for the flaw.

What CVE-2026-77770 Actually Breaks

The plugin’s email-verification link handler deleted WordPress options using names pulled straight from the request, without checking whether the person making the request had ever logged in or held a valid nonce. An attacker could point a single crafted link at that handler and wipe out options the site depends on.

That is a strange thing for a two-factor plugin to get wrong, because the options at risk include the plugin’s own configuration. Deleting the right keys can disable miniOrange 2FA outright, stripping the exact login protection a site installed the plugin to get. Deleting others can knock out admin access to the dashboard entirely, since some of WordPress’s own core options can be targeted the same way.

The vendor’s changelog for 6.3.1 lists the fix alongside a second patch, for a client-controlled counter that let attackers bypass the 2FA lockout after repeated failed attempts and a missing rate limit on the configuration-validation endpoint. Neither of those carries its own CVE as severe as the option-deletion bug, but both point the same direction: the access-control logic around this plugin’s verification flows needed a real audit, not a patch here and there.

Who Needs to Update

Anyone running miniOrange 2FA, Two-Factor Authentication for WordPress. Check the version under Plugins in wp-admin: anything before 6.3.1 on the free track or 19.3 on Pro is exposed. The current release on the WordPress.org repository is already 6.3.1, so a normal “update plugins” pass clears it, which is the easiest fix available here, not a workaround.

There is no indication yet of in-the-wild exploitation, but an unauthenticated, no-interaction bug that can lock out every admin on a site tends not to stay quiet for long once a proof of concept circulates. Sites that can’t update immediately should at minimum confirm they have a working path back into wp-admin that does not depend on the plugin, in case someone gets there first.

This is also a good prompt to look past just this one plugin. Any plugin that handles login, password reset, or account verification is effectively part of a site’s access-control layer, and a gap in one of those flows is worse than the same bug in a feature that doesn’t touch authentication. Clients who want that layer checked rather than assumed safe are usually better served by a proper audit through WordPress development work than by waiting for the next CVE to land. Two other access-control bugs worth knowing if you manage WordPress sites: TranslatePress’s password-reset takeover flaw from last month, and Ultimate Member’s privilege escalation bug, both in the same family of “the login flow trusted something it shouldn’t have.”

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

News & Updates

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a…

Aftab Memon

October 3, 2026

News & Updates

A laptop glowing with a soft magenta light next to an ID keycard on a wooden desk, symbolizing a WordPress admin access vulnerability

Elementor Patches a Critical CSRF Flaw That Could Hand Attackers Admin Access (CVE-2026-62062)

A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062, CVSS 8.8) let attackers create admin accounts with one click. Patched…

Aftab Memon

October 2, 2026

Plugins

Stack of to-do list task cards with checkboxes in front of a faded kanban board, illustrating WordPress dashboard to-do list and task management plugins

How to Add a To-Do List to Your WordPress Dashboard (4 Plugins Compared)

Compare four real WordPress plugins for a dashboard to-do list or task board, from a simple single-person widget to full…

Husen Memon

October 2, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant