All verified exploits

CVE-2026-77770 miniOrange 2FA Unauthenticated Arbitrary Option Deletion

Deterministic critical WordPress Added cve-verified-cve-2026-77770

Detects the miniOrange 2FA WordPress plugin (5.3.24–6.3.0 free track, 18.0–19.2 premium track) vulnerable to unauthenticated arbitrary WordPress option deletion. The plugin registers its out-of-band email-verification link handler on the init hook (fired for every request), and when ?Txid and ?accessToken are present it uses the ?userID and ?Txid request parameters directly as site-option names passed to delete_site_option() — with no login, nonce, or capability check. Any anonymous visitor can delete options such as siteurl, template, or active_plugins, locking every administrator out of wp-admin or disabling security plugins (CWE-862, CVSS 10.0). Update miniOrange 2FA to 6.3.1 (free) or 19.3 (premium) or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-77770?

Scan your domain free