{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aminiorangeotp_login_verification_and_sms_notifications/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:miniorange:otp_login_verification_and_sms_notifications:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85984"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OTP Login, Verification and SMS Notifications (\u003c= 5.5.5)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","cve-2026-85984"],"_cs_type":"advisory","_cs_vendors":["miniOrange"],"content_html":"\u003cp\u003eThe miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress (all versions up to and including 5.5.5) contains a critical authentication bypass vulnerability identified as CVE-2026-85984. The flaw resides within the mo_by_pass_login() function, where improper handling of the mo_wp_login_intent POST parameter allows an authentication bypass when specific administrative configurations are active. If a site administrator has enabled 'WP Login OTP', 'Login with Only OTP', 'Allow Users to Login with Username and Password', and 'Admin OTP Bypass', the system fails to validate credentials. An attacker simply provides a valid administrative username and the parameter mo_wp_login_intent=otp. The plugin erroneously skips the standard wp_authenticate_username_password() check and resolves the WP_User account solely based on the username, granting full access without a password or OTP verification. This vulnerability poses a severe risk to WordPress instances configured with these specific security settings.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to gain full administrative access to the affected WordPress site. This provides the attacker with complete control over the site content, user management, and plugin configuration, which could lead to further compromise through malicious plugin uploads, data exfiltration, or complete site takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of the miniOrange OTP Login, Verification and SMS Notifications plugin to a version beyond 5.5.5. If patching is not immediately feasible, disable the 'Admin OTP Bypass' option within the plugin settings to mitigate the primary vector for this bypass. Review administrative account login logs for suspicious activity occurring without standard password-based authentication steps.\u003c/p\u003e\n","date_modified":"2026-09-26T19:00:02Z","date_published":"2026-09-26T19:00:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-miniorange-bypass/","summary":"An authentication bypass vulnerability in the miniOrange OTP Login, Verification and SMS Notifications plugin allows unauthenticated attackers to log in as administrators by abusing a flawed login intent parameter.","title":"Authentication Bypass in miniOrange OTP Login Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-miniorange-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:miniorange:otp_login_verification_and_sms_notifications:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}