← Back to search

CVE-2026-85984

9.8 CRITICAL

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows unauthenticated attackers to bypass authentication by exploiting the mo_wp_login_intent parameter in the miniOrange OTP plugin, enabling them to log in as any existing administrator account.
Exploitability
Exploitation is conditional on specific plugin settings being enabled, making it moderately difficult to exploit.
Blast radius
If exploited, the impact is high, as it allows unauthorized access to administrator accounts, potentially leading to full control of the WordPress site.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or upgrade to version 5.5.6 or later.
auth-bypasswebwordpressplugin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mo_wp_login_intent is submitted with the value otp, causing mo_get_user() to skip wp_authenticate_username_password() and resolve a WP_User purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mo_wp_login_intent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.