Known vulnerabilities in miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)
Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push Notification & passwordless login.
9Reported vulnerabilities
8.8Highest CVSS score
6.2.9Latest version
10,000+Active installs
What to do now
Update miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) to 6.2.7 or later.
9 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-42461 | High | 0.7% | Before 5.6.2 | 5.6.2 |
November 18, 2022 |
| WF-ed117fb8-c13a-4088-aa33-8d44fc5dcf37 | High | — | 5.6.1 and earlier | 5.6.2 |
November 1, 2022 |
| CVE-2022-44589 | High | 0.7% | Before 5.6.2 | 5.6.2 |
December 29, 2023 |
| WF-52a03c45-1d65-43aa-b30f-13698019e05f | Medium | — | 5.5.82 and earlier | 5.6.0 |
September 16, 2022 |
| WF-bb929679-85bb-4d5b-9a99-e6081d55019f | Medium | — | 5.5.7 and earlier | 5.5.75 |
June 27, 2022 |
| WF-f810326f-f84a-4066-aa28-5caa915ba877 | Medium | — | 5.4.39 and earlier | 5.4.40 |
August 10, 2021 |
| CVE-2026-12695 | Medium | 0.3% | Before 6.2.6 | 6.2.6 |
July 15, 2026 |
| CVE-2026-16035 | Medium | 0.2% | 6.2.6 and earlier | 6.2.7 |
July 27, 2026 |
| CVE-2025-54745 | Medium | 0.3% | 6.1.1 and earlier | 6.1.2 |
August 23, 2025 |