CRITICAL 10.0 NVD
CVE-2026-77770
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site op
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
References
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-09-10 via NVD.
Risk Timeline
CVE Disclosed2026-09-10 · 0 days ago
Remediation Resources
Official Advisory
wpscan.com/vulnerability/68bc7294-1ee6-44a9-9995-3b23b921f750/
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.