← Back to search

CVE-2026-16036

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows an attacker to rebind a user's second factor to their own account if they know the user’s password, enabling unauthorized access.
Exploitability
Exploitation requires knowledge of the user’s password and access to the miniOrange 2FA WordPress plugin version before 6.2.7, making it moderately difficult.
Blast radius
If exploited, this can lead to full account takeover, including admin accounts, with significant impact on affected systems.
Prioritized remediation
Update the miniOrange 2FA WordPress plugin to version 6.2.7 or later immediately.
auth-bypasswebwordpress

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-287

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.