miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass
CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6.
miniOrange OTP Login, Verification and SMS Notifications versions 5.5.5 and earlier contain a conditional authentication bypass that can let an unauthenticated attacker log in as an existing WordPress administrator. The issue is tracked as CVE-2026-85984, carries a 9.8 Critical CVSS score, and is fixed in version 5.5.6.
Vulnerability summary
- Product: miniOrange OTP Login, Verification and SMS Notifications
- Affected versions: 5.5.5 and earlier
- Fixed version: 5.5.6
- CVE: CVE-2026-85984
- Severity: Critical, CVSS 9.8
- Attack class: Authentication bypass leading to administrator account takeover
- Authentication required: No
- Exploit prerequisite: A specific combination of OTP, password fallback, and administrator-bypass settings must be enabled
How the authentication bypass occurs
The vulnerable branch is in the plugin’s password-bypass login handling. Wordfence reports that an unauthenticated request could set the mo_wp_login_intent input so the plugin treated the request as an OTP login while skipping the normal WordPress username-and-password authentication path.
In the affected configuration, the plugin could resolve a WordPress user from a supplied username and accept administrator role membership as sufficient, without validating either the account password or an OTP. A known administrator username could therefore be enough to take over the account.
Configuration prerequisites
Wordfence states that exploitation requires all four of these plugin options to be enabled at the same time:
- WP Login OTP
- Login with Only OTP
- Allow Users to Login with Username and Password
- Admin OTP Bypass
Sites that do not use this exact combination are not known to be exploitable through this path, but every installation running 5.5.5 or earlier should still update because security settings can change and the vulnerable code remains present.
Immediate remediation
- Update miniOrange OTP Verification to 5.5.6 or later immediately.
- Until the update is complete, disable Admin OTP Bypass or deactivate the plugin.
- Review all administrator accounts and active sessions, then force password resets and session revocation if suspicious access is found.
- Purge page, object, and CDN caches after updating, especially where login pages or authentication responses may be cached.
Verify and update with WP-CLI
wp plugin get miniorange-otp-verification --field=version
wp plugin update miniorange-otp-verification
wp plugin get miniorange-otp-verification --field=version
The final version must be 5.5.6 or newer. Then test administrator, editor, and subscriber login flows in a private browser session to confirm that every configured method requires the intended credential or OTP.
Hunt for suspicious authentication activity
Review access, WAF, and authentication logs for requests containing mo_wp_login_intent, especially when followed by successful access to /wp-admin/ from a new address or user agent. This defensive search finds the relevant request marker without reproducing an exploit:
grep -Ei 'mo_wp_login_intent' access.log*
Also inspect recent administrator registrations and account metadata:
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp user session list <admin-user-id>
wp plugin list --status=active
wp plugin list --status=must-use
wp cron event list
Check for unexpected administrator accounts, password or email changes, unfamiliar application passwords, newly installed plugins, must-use plugins, scheduled persistence, and modified theme or plugin files.
Response if compromise is suspected
Preserve web-server, security, and WordPress activity logs before cleanup. Revoke sessions for affected administrators, rotate administrator and hosting credentials, remove unauthorized application passwords, replace modified code with trusted packages, and verify WordPress core checksums. If the attacker gained administrator access, treat the incident as a full site compromise rather than only an account problem.
wp core verify-checksums
wp plugin verify-checksums --all
Checksum results for premium or custom plugins may require comparison with fresh vendor packages.
Sources
- Wordfence Intelligence vulnerability record
- miniOrange OTP Verification on WordPress.org
- CVE-2026-85984
This article summarizes public Wordfence research and provides defensive remediation guidance. WPDeeply did not discover this vulnerability.