<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-85984 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-85984/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 19:00:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-85984/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in miniOrange OTP Login Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-miniorange-bypass/</link><pubDate>Sat, 26 Sep 2026 19:00:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-miniorange-bypass/</guid><description>An authentication bypass vulnerability in the miniOrange OTP Login, Verification and SMS Notifications plugin allows unauthenticated attackers to log in as administrators by abusing a flawed login intent parameter.</description><content:encoded><![CDATA[<p>The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress (all versions up to and including 5.5.5) contains a critical authentication bypass vulnerability identified as CVE-2026-85984. The flaw resides within the mo_by_pass_login() function, where improper handling of the mo_wp_login_intent POST parameter allows an authentication bypass when specific administrative configurations are active. If a site administrator has enabled 'WP Login OTP', 'Login with Only OTP', 'Allow Users to Login with Username and Password', and 'Admin OTP Bypass', the system fails to validate credentials. An attacker simply provides a valid administrative username and the parameter mo_wp_login_intent=otp. The plugin erroneously skips the standard wp_authenticate_username_password() check and resolves the WP_User account solely based on the username, granting full access without a password or OTP verification. This vulnerability poses a severe risk to WordPress instances configured with these specific security settings.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to gain full administrative access to the affected WordPress site. This provides the attacker with complete control over the site content, user management, and plugin configuration, which could lead to further compromise through malicious plugin uploads, data exfiltration, or complete site takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate update of the miniOrange OTP Login, Verification and SMS Notifications plugin to a version beyond 5.5.5. If patching is not immediately feasible, disable the 'Admin OTP Bypass' option within the plugin settings to mitigate the primary vector for this bypass. Review administrative account login logs for suspicious activity occurring without standard password-based authentication steps.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>authentication-bypass</category><category>cve-2026-85984</category></item></channel></rss>