CRITICAL
10 CVE-2026-77770 Published 10 Sept 2026
WordPress miniOrange 2FA Plugin Option Deletion Vulnerability
Worried this affects one of your servers?
The miniOrange 2FA WordPress plugin, prior to versions 6.3.1 and 19.3, does not validate input before deleting site options, allowing any visitor to remove arbitrary options.
This can result in administrators being locked out of the dashboard or the plugin being deactivated.
Reference: CVE-2026-77770 on NVD
← Back to Security News