POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-85984 — WordPress miniOrange OTP Unauthenticated Admin Bypass

September 28, 2026 · 87 views

Unauthenticated authentication bypass (CWE-287) in miniOrange OTP Login, Verification and SMS Notifications ≤ 5.5.5 via wp-login.php POST mo_wp_login_intent=otp with empty password — mo_by_pass_login() skip_pass_fallback skips password check when Admin OTP Bypass and related OTP login options are enabled. CVSS 3.1 9.8 Critical. Fixed in 5.5.6+. PoC: plugin scan, optional user enum, check/exploit modes.

#wordpress#miniorange#otp#auth-bypass#unauthenticated#plugin

CVE:

CVE-2026-85984

Date:

2026-09-28

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-85984 affects miniOrange OTP Login, Verification and SMS Notifications (WordPress plugin slug miniorange-otp-verification) ≤ 5.5.5. An unauthenticated attacker can obtain an administrator session by posting to wp-login.php with mo_wp_login_intent=otp, a valid admin username, and an empty password (CWE-287).

In the skip_pass_fallback branch of mo_by_pass_login(), the plugin skips wp_authenticate_username_password(), resolves the user by username only, and treats administrator role as sufficient when Admin OTP Bypass and related options are enabled.

| | | |---|---| | Plugin | miniorange-otp-verification | | Affected | ≤ 5.5.5 | | Fixed | 5.5.6+ | | Vector | wp-login.php + mo_wp_login_intent=otp | | Impact | Full site compromise (admin session) | | CVSS 3.1 | 9.8 Critical (AV:N/AC:L/PR:N/UI:N) |

Conditions (site admin must have enabled all):

  1. WP Login OTP
  2. Login with Only OTP
  3. Allow Users to Login with Username and Password
  4. Admin OTP Bypass

Credit: Wordfence CNA; finder Supakiad S. / m3ez.

Open source PoC: https://github.com/murrez/CVE-2026-85984

PoC page: https://pocbit.org/pocs/cve-2026-85984

Bundled tool (Python 3)

pip install -r requirements.txt

python poc.py -u https://wordpress.example --mode check
python poc.py -u https://wordpress.example --mode check --probe-login
python poc.py -u https://wordpress.example --mode exploit --username admin
python poc.py --list targets.example.txt --mode exploit -j 8
python poc.py -u https://wordpress.example --mode exploit --no-color

Asset discovery

body="/wp-content/plugins/miniorange-otp-verification"
body="mo_wp_login_intent"

Impact

Internet-facing WordPress sites with vulnerable plugin versions and the misconfigured OTP bypass options may allow unauthenticated admin takeover without knowing the password.

Remediation

  1. Upgrade miniOrange OTP to 5.5.6 or newer immediately.
  2. Disable Admin OTP Bypass unless strictly required; review all four OTP login settings.
  3. After patch, rotate all administrator passwords and review recent admin sessions / file changes.

Legal and ethical use

Authorized testing only. Do not attempt bypass on sites you do not own or lack written permission to test.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →