---
id: CVE-2026-77770
title: >-
  The miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 2FA  WordPress
  plugin before 19.3 does not require a validated transaction before deleting
  site options whose names come from unauthenticated request input, allowing any
  visit…
summary: >-
  The miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 2FA  WordPress
  plugin before 19.3 does not require a validated transaction before deleting
  site options whose names come from unauthenticated request input, allowing any
  visit…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H'
cwe:
  - CWE-862
product: miniOrange 2FA
affected:
  - miniorange_2fa >= 5.3.24 < 6.3.1
  - miniorange_2fa >= 18.0 < 19.3
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77770'
references:
  - url: 'https://wpscan.com/vulnerability/68bc7294-1ee6-44a9-9995-3b23b921f750/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T13:08:43.647602Z'
ingestedAt: '2026-09-10T06:34:51.924Z'
epss: 0.00437
epssPercentile: 0.35395
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/cflowsec/CVE-2026-77770'
  checkedAt: '2026-09-26T09:06:00.726Z'
exploitAvailable: true
---

## Overview

The miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 2FA  WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 2FA  WordPress plugin before 19.3 on the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
