What is CVE-2026-16036?
CVE-2026-16036 is a critical vulnerability in the miniOrange 2FA WordPress plugin before version 6.2.7, caused by failure to bind the second factor to the target account during pre-login challenges. This allows an attacker who knows a user's password to rebind the second factor to an attacker-controlled destination, bypassing two-factor authentication. Affected users must immediately update the plugin to version 6.2.7 or later.
Azərbaycanca: CVE-2026-16036, miniOrange 2FA WordPress plagininin 6.2.7-dən əvvəlki versiyalarında aşkarlanan kritik zəiflikdir. Bu, autentifikasiya zamanı ikinci faktorun düzgün bağlanmaması səbəbindən, istifadəçi şifrəsini bilən hücumçunun həmin istifadəçinin 2FA-nı öz nəzarətindəki ünvana yönləndirməsinə imkan verir. Təsirə məruz qalan sayt sahibləri dərhal plaqini 6.2.7 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: miniOrange
FAQ2
Why is CVE-2026-16036 considered critical in the miniOrange 2FA plugin?
Because the second factor is not properly bound during authentication, allowing an attacker who knows a user's password to rebind the 2FA to an attacker-controlled destination and bypass two-factor authentication.
Which version of the miniOrange 2FA plugin fixes the CVE-2026-16036 vulnerability?
Version 6.2.7 or later fixes this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.