CVE-CVE-2026-85984
Severity
CRITICAL
CVSS Score
9.8
Description
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mo_wp_login_intent is sub...
PoCs for CVE-CVE-2026-85984
CVE-2026-85984
General
Python
0
murrez
2026-09-28