Detects the miniOrange 2FA WordPress plugin (5.3.24–6.3.0 free track, 18.0–19.2 premium track) vulnerable to unauthenticated arbitrary WordPress option deletion. The plugin registers its out-of-band email-verification link handler on the init hook (fired for every request), and when ?Txid and ?accessToken are present it uses the ?userID and ?Txid request parameters directly as site-option names passed to delete_site_option() — with no login, nonce, or capability check. Any anonymous visitor can delete options such as siteurl, template, or active_plugins, locking every administrator out of wp-admin or disabling security plugins (CWE-862, CVSS 10.0). Update miniOrange 2FA to 6.3.1 (free) or 19.3 (premium) or later.
Is your app exploitable through CVE-2026-77770?
Scan your domain free