What is CVE-2026-16619?
This vulnerability affects the miniOrange 2FA WordPress plugin. It fails to properly limit second-factor verification attempts, allowing an attacker who knows the user's password to brute-force the one-time code. Update the plugin to version 6.2.8 or later.
Azərbaycanca: Bu CVE, miniOrange 2FA WordPress plagini təsir edir. Təcavüzkar istifadəçi şifrəsini bildikdə, ikinci faktor doğrulama cəhdlərinin say məhdudiyyətini keçərək bir dəfəlik kodu təxmin edə bilər. Plagin 6.2.8 versiyasına yenilənməlidir.
Related CVEs
link basis: shared vendor: miniOrange
FAQ2
What must an attacker know in advance to exploit CVE-2026-16619?
To exploit this vulnerability and brute-force the one-time code, the attacker must know the user's password.
To which version should the miniOrange 2FA plugin be updated to fix CVE-2026-16619?
The plugin should be updated to version 6.2.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.