A WordPress OTP plugin bug lets anyone log in as admin, no patch yet
A critical authentication bypass in the miniOrange OTP Login plugin lets an attacker sign in as any administrator with just a username, no password or OTP check required, and there is no fix out yet.
Wordfence disclosed a critical authentication bypass in miniOrange OTP Login, Verification and SMS Notifications, a WordPress two-factor plugin, on 26 September. There is no patched version yet.
The flaw, CVE-2026-85984 (CVSS 9.8), sits in the plugin’s mo_by_pass_login() function. When an unauthenticated request submits mo_wp_login_intent=otp, the function checks only whether the target account is an administrator and skips password and OTP verification entirely, so a known username and an empty password are enough to sign in as that admin. It affects every version up to and including 5.5.5, but only bites when a site has WP Login OTP, Login with Only OTP, “Allow Users to Login with Username and Password”, and Admin OTP Bypass all switched on together. Wordfence credits researcher Supakiad S. and says it notified the vendor on 4 September, three weeks before publishing with still no fix shipped.
Why it matters: if you or a client runs this plugin, check those four settings now rather than waiting on a patch that doesn’t exist. Turning off Admin OTP Bypass or the username/password fallback closes the hole without needing an update.
The caveat: Wordfence hasn’t confirmed active exploitation, and the bug only triggers under that specific settings combination. But a CVSS 9.8, unauthenticated admin-login bypass with the vulnerable function and parameter already public is exactly the kind of bug that gets scanned for within days.