{"id":"CVE-2026-16035","published":"2026-08-04T07:16:29.370","lastModified":"2026-08-04T18:16:45.377","description":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/26217efe-b867-4bb9-ac7c-765fb796e2c1/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}