Extension WordPress
Vulnérabilités miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)
Cette page rassemble les failles publiées pour miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)
10 fiches
miniOrange's Google Authenticator <= 6.1.1 – Missing Authorization
The miniOrange 2-factor Authentication (2FA with SMS, Email, Google Authenticator) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.1. This makes it…
*-6.1.1
6.1.2
23/08/2025
miniOrange's Google Authenticator <= 5.6.5 – Missing Authorization to Plugin Settings Change
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change…
*-5.6.5
5.6.6
19/04/2023
miniOrange's Google Authenticator <= 5.6.1 – Sensitive Data Exposure of Multifactor Backup Codes
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.6.1 via functions such as 'mo_wpns_get_progress' and 'mo2f_use_backup_codes'. This can allow attackers to extract sensitive data about multifactor authentication…
*-5.6.1
5.6.2
23/11/2022
miniOrange's Google Authenticator <= 5.6.1 – Cross-Site Request Forgery to Malware Scan Termination
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on the mo_wpns_stop_scan function. This makes it possible for…
*-5.6.1
5.6.2
01/11/2022
miniOrange's Google Authenticator <= 5.6.1 – Missing Authorization to Plugin Settings Change
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.1. This makes it possible for authenticated attackers, with subscriber-level…
*-5.6.1
5.6.2
31/10/2022
miniOrange's Google Authenticator <= 5.5.82 – Missing Authorization
miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an the mo_wpns_malware_redirect function in versions up to, and including, 5.5.82. This makes it possible for authenticated attackers, with subscriber-level…
*-5.5.82
5.6.0
16/09/2022
miniOrange's Google Authenticator <= 5.5.7 – Reflected Cross-Site Scripting
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.7. This makes it possible for attackers…
*-5.5.7
5.5.75
27/06/2022
miniOrange's Google Authenticator <= 5.5.5 – Authenticated (Admin+) Cross-Site Scripting
The miniOrange's Google Authenticator plugin for WordPress vulnerable to Stored Cross-Site Scripting via the ‘Add Referer’ field in versions up to, and including, 5.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-5.5.5
5.5.6
06/06/2022
miniOrange's Google Authenticator <= 5.4.52 – Unauthenticated Arbitrary Options Deletion
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary…
*-5.4.52
5.5
28/02/2022
miniOrange's Google Authenticator <= 5.4.39 – Cross-Site Scripting
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user’ parameter in versions up to, and including, 5.4.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-5.4.39
5.4.40
10/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.