CVE-2026-77770
Last modified
CVE-2026-77770 is a critical-severity vulnerability rated 10/10 on the CVSS scale. The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | miniOrange 2FA | >= 5.3.24, < 6.3.1 |
| Unknown | miniOrange 2FA | >= 18.0, < 19.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77770?
How severe is CVE-2026-77770?
How do I fix CVE-2026-77770?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77764The GamiPress WordPress plugin before 7.9.9.6 does not prop…4.3
- CVE-2026-77765The Better Payment WordPress plugin before 2.3.4 does not v…5.3
- CVE-2026-77766The Directorist: AI-Powered Business Directory, Listings & C…4.3
- CVE-2026-77767Reconmap's API applies a fallback authorization policy in ap…7.5
- CVE-2026-77768The report.get procedure in packages/trpc/src/routers/report…6.5
- CVE-2026-77769The report.list procedure in packages/trpc/src/routers/repor…6.5
- CVE-2026-77771The miniOrange 2FA WordPress plugin before 6.3.1, miniOrang…7.5
- CVE-2026-77773The Contact Form to Chat Apps | Click to Chat to Order Word…5.3
- CVE-2026-77774Adobe Commerce is affected by an Incorrect Authorization vul…8.6
- CVE-2026-77775Headroom's LLM proxy lets a client choose the upstream desti…8.6
- CVE-2026-77776Headroom's LLM proxy derives the memory owner from the x-hea…9.1
- CVE-2026-7778An issue that could allow a dashboard configuration to be vi…5
Are you affected by CVE-2026-77770?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
