What is CVE-2026-16035?
The miniOrange 2FA WordPress plugin before version 6.2.7 lacks restrictions on triggering second-factor OTP sends and does not bind the recipient to the enrolling user's address. This allows low-privileged users to send one-time passcodes to arbitrary emails and potentially exhaust the site's sending limits. Update the plugin immediately.
Azərbaycanca: miniOrange 2FA WordPress plaqini 6.2.7-dən əvvəlki versiyalarda ikinci faktor OTP göndərmə əməliyyatını kimin başlada biləcəyini məhdudlaşdırmır. Bu, aşağı səlahiyyətli istifadəçilərə ixtiyari e-poçt ünvanlarına birdəfəlik kodlar göndərməyə, e-poçt limitlərini doldurmağa imkan verir. Plaqini son versiyaya yeniləmək mütləqdir.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
What vulnerability does the miniOrange 2FA plugin have?
The plugin before version 6.2.7 suffers from unrestricted second-factor OTP sending, which allows low-privileged users to send one-time passcodes to arbitrary email addresses and potentially exhaust the site's sending limits.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.