ConicPlex

Start Your Project

A laptop glowing WordPress blue on a desk beside a broken keycard and an open padlock, symbolizing a WordPress plugin access-control vulnerability

On this Page

miniOrange 2FA Plugin Patches a Maximum-Severity Option-Deletion Flaw (CVE-2026-77770)

miniOrange 2FA patched CVE-2026-77770, a CVSS 10.0 flaw letting anyone delete WordPress options and lock out admins or disable 2FA. Update to 6.3.1 or 19.3.

Aftab Memon

September 12, 2026

The miniOrange 2FA plugin, installed on more than 10,000 WordPress sites to add two-factor login protection, shipped a fix on September 7, 2026 for a maximum-severity flaw that let anyone, logged in or not, delete arbitrary WordPress options on the site. Tracked as CVE-2026-77770 and assigned a CVSS score of 10.0, the bug sat in versions before 6.3.1 of the free edition and before 19.3 of the Pro edition, according to NVD’s entry for the flaw.

What CVE-2026-77770 Actually Breaks

The plugin’s email-verification link handler deleted WordPress options using names pulled straight from the request, without checking whether the person making the request had ever logged in or held a valid nonce. An attacker could point a single crafted link at that handler and wipe out options the site depends on.

That is a strange thing for a two-factor plugin to get wrong, because the options at risk include the plugin’s own configuration. Deleting the right keys can disable miniOrange 2FA outright, stripping the exact login protection a site installed the plugin to get. Deleting others can knock out admin access to the dashboard entirely, since some of WordPress’s own core options can be targeted the same way.

The vendor’s changelog for 6.3.1 lists the fix alongside a second patch, for a client-controlled counter that let attackers bypass the 2FA lockout after repeated failed attempts and a missing rate limit on the configuration-validation endpoint. Neither of those carries its own CVE as severe as the option-deletion bug, but both point the same direction: the access-control logic around this plugin’s verification flows needed a real audit, not a patch here and there.

Who Needs to Update

Anyone running miniOrange 2FA, Two-Factor Authentication for WordPress. Check the version under Plugins in wp-admin: anything before 6.3.1 on the free track or 19.3 on Pro is exposed. The current release on the WordPress.org repository is already 6.3.1, so a normal “update plugins” pass clears it, which is the easiest fix available here, not a workaround.

There is no indication yet of in-the-wild exploitation, but an unauthenticated, no-interaction bug that can lock out every admin on a site tends not to stay quiet for long once a proof of concept circulates. Sites that can’t update immediately should at minimum confirm they have a working path back into wp-admin that does not depend on the plugin, in case someone gets there first.

This is also a good prompt to look past just this one plugin. Any plugin that handles login, password reset, or account verification is effectively part of a site’s access-control layer, and a gap in one of those flows is worse than the same bug in a feature that doesn’t touch authentication. Clients who want that layer checked rather than assumed safe are usually better served by a proper audit through WordPress development work than by waiting for the next CVE to land. Two other access-control bugs worth knowing if you manage WordPress sites: TranslatePress’s password-reset takeover flaw from last month, and Ultimate Member’s privilege escalation bug, both in the same family of “the login flow trusted something it shouldn’t have.”

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Software

Marble consultation counter in a med spa with a tablet, orchid, treatment cards, and a towel, with a treatment room visible in the background

Why a Treatment-Finder Quiz Converts Better Than a Service Menu for Med Spas and Clinics

A treatment-finder quiz can convert far better than a static service list on a med spa or clinic website. Here…

Aftab Memon

September 12, 2026

Plugins

Illustration of a notification bell above a stack of product boxes, representing WooCommerce back in stock notification plugins

Best WooCommerce Back in Stock Notification Plugins: 4 Real Options Compared

WooCommerce has no built-in way to notify a customer when an out-of-stock product comes back. This post compares four real…

Husen Memon

September 11, 2026

News & Updates

A laptop glowing with soft blue, red, yellow, and green light beside a cracked glass cube on a desk, symbolizing a breached browser security boundary

Chrome Patches Its Seventh Actively Exploited Zero-Day of 2026 (CVE-2026-87491)

Google patched CVE-2026-87491, Chrome’s seventh actively exploited zero-day of 2026, in Chrome 153. Here’s what changed and how to update….

Sameer Malek

September 10, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant