System running
Last check: 2026-09-29 00:26:08 | Auto-updates every hour
754 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-2026-85984

CVE-2026-85984 General Python #poc #github #cve-2026-85984 #general
Author
murrez
Published
2026-09-28
Stars
0
Forks
0
Description

CVE-2026-85984 PoC: WordPress miniOrange OTP ≤5.5.5 unauth admin bypass (mo_wp_login_intent=otp + empty password). Check/exploit, user enum, colored CLI. https://pocbit.org/pocs/cve-2026-85984

CVE-CVE-2026-85984 Details
Severity
CRITICAL
CVSS Score
9.8
CWE
CWE-287
Description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mo_wp_login_intent is sub...

Related PoCs for CVE-2026-85984

No other PoCs found for this CVE.

Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources