CVE-2026-85984 — WordPress miniOrange OTP Unauthenticated Admin Bypass
September 28, 2026 · 87 views
Unauthenticated authentication bypass (CWE-287) in miniOrange OTP Login, Verification and SMS Notifications ≤ 5.5.5 via wp-login.php POST mo_wp_login_intent=otp with empty password — mo_by_pass_login() skip_pass_fallback skips password check when Admin OTP Bypass and related OTP login options are enabled. CVSS 3.1 9.8 Critical. Fixed in 5.5.6+. PoC: plugin scan, optional user enum, check/exploit modes.
Description
Overview
CVE-2026-85984 affects miniOrange OTP Login, Verification and SMS Notifications (WordPress plugin slug miniorange-otp-verification) ≤ 5.5.5. An unauthenticated attacker can obtain an administrator session by posting to wp-login.php with mo_wp_login_intent=otp, a valid admin username, and an empty password (CWE-287).
In the skip_pass_fallback branch of mo_by_pass_login(), the plugin skips wp_authenticate_username_password(), resolves the user by username only, and treats administrator role as sufficient when Admin OTP Bypass and related options are enabled.
| | |
|---|---|
| Plugin | miniorange-otp-verification |
| Affected | ≤ 5.5.5 |
| Fixed | 5.5.6+ |
| Vector | wp-login.php + mo_wp_login_intent=otp |
| Impact | Full site compromise (admin session) |
| CVSS 3.1 | 9.8 Critical (AV:N/AC:L/PR:N/UI:N) |
Conditions (site admin must have enabled all):
- WP Login OTP
- Login with Only OTP
- Allow Users to Login with Username and Password
- Admin OTP Bypass
Credit: Wordfence CNA; finder Supakiad S. / m3ez.
Open source PoC: https://github.com/murrez/CVE-2026-85984
PoC page: https://pocbit.org/pocs/cve-2026-85984
Bundled tool (Python 3)
pip install -r requirements.txt
python poc.py -u https://wordpress.example --mode check
python poc.py -u https://wordpress.example --mode check --probe-login
python poc.py -u https://wordpress.example --mode exploit --username admin
python poc.py --list targets.example.txt --mode exploit -j 8
python poc.py -u https://wordpress.example --mode exploit --no-color
Asset discovery
body="/wp-content/plugins/miniorange-otp-verification"
body="mo_wp_login_intent"
Impact
Internet-facing WordPress sites with vulnerable plugin versions and the misconfigured OTP bypass options may allow unauthenticated admin takeover without knowing the password.
Remediation
- Upgrade miniOrange OTP to 5.5.6 or newer immediately.
- Disable Admin OTP Bypass unless strictly required; review all four OTP login settings.
- After patch, rotate all administrator passwords and review recent admin sessions / file changes.
Legal and ethical use
Authorized testing only. Do not attempt bypass on sites you do not own or lack written permission to test.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-14281critical
CVE-2026-14281 — WAWP WordPress Unauthenticated Privilege Escalation (≤ 4.8.6)
Unauthenticated administrator via public WAWP REST signup: unsanitized wawp_custom_fields writes wp_capabilities through update_user_meta. Automation Web Platform plugin ≤ 4.8.6 (CVSS 3.1 9.8 Critical).
- WordPressCVE-2026-92229high
CVE-2026-92229 — Forminator ≤ 1.57.2 Unauthenticated Shortcode Execution
Unauthenticated arbitrary shortcode execution in **Forminator** (≤ 1.57.2) via **`current_url`** in quiz-related AJAX handlers.
- WordPressCVE-2026-82901critical
CVE-2026-82901 — Ultra Addons for Contact Form 7 Unauthenticated File Upload
Unauthenticated arbitrary file upload (CWE-434, CVSS 3.1 9.8 Critical) in Ultra Addons for Contact Form 7 (Themefic) ≤ 3.5.50 via uacf7_wpcf7_mail_components in the PDF Generator addon — signature field copies files to wp-content/uploads/uacf7-uploads/ with weak validation. Requires PDF Generator enabled on a form with uacf7_signature. Fixed in 3.5.51+.
- WordPressCVE-2026-12227high
CVE-2026-12227 — Visual Composer Website Builder ≤ 45.16.0 Unauthenticated LFI
Unauthenticated local file inclusion in **Visual Composer Website Builder** (≤ 45.16.0) via the **`vcv-template`** parameter (public Wordfence/NVD discussion).