CVE-2026-85984

CVE-2026-85984 published: The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the ...

View full NVD advisory → ← Back to CVE watch